CVE-2018-16476
Summary
| CVE | CVE-2018-16476 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-30 19:29:00 UTC |
| Updated | 2019-10-09 23:36:00 UTC |
| Description | A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Cloudforms | 4.6 | All | All | All |
| Application | Redhat | Cloudforms | 4.6 | All | All | All |
| Application | Rubyonrails | Rails | All | All | All | All |
| Application | Rubyonrails | Rails | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Google Groups | MISC | groups.google.com | Exploit, Mailing List, Mitigation, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| Rails 4.2.11, 5.0.7.1, 5.1.6.1 and 5.2.1.1 have been released! | Riding Rails | MISC | weblog.rubyonrails.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.