Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-16476


A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.


Published

2018-11-30T19:29:00.220

Last Modified

2024-11-21T03:52:49.880

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rubyonrails rails < 4.2.11 Yes
Application rubyonrails rails < 5.0.7.1 Yes
Application rubyonrails rails < 5.1.6.1 Yes
Application rubyonrails rails < 5.2.1.1 Yes
Application redhat cloudforms 4.6 Yes

References