{"schema_version":"1.7.3","id":"GHSA-q2qw-rmrh-vv42","published":"2018-12-05T17:24:27Z","modified":"2024-02-17T05:33:12.879561Z","aliases":["CVE-2018-16476"],"summary":"Improper Access Control in activejob","details":"A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have.","affected":[{"package":{"name":"activejob","ecosystem":"RubyGems","purl":"pkg:gem/activejob"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2.0"},{"fixed":"4.2.11"}]}],"versions":["4.2.0","4.2.1","4.2.1.rc1","4.2.1.rc2","4.2.1.rc3","4.2.1.rc4","4.2.10","4.2.10.rc1","4.2.2","4.2.3","4.2.3.rc1","4.2.4","4.2.4.rc1","4.2.5","4.2.5.1","4.2.5.2","4.2.5.rc1","4.2.5.rc2","4.2.6","4.2.6.rc1","4.2.7","4.2.7.1","4.2.7.rc1","4.2.8","4.2.8.rc1","4.2.9","4.2.9.rc1","4.2.9.rc2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-q2qw-rmrh-vv42/GHSA-q2qw-rmrh-vv42.json"}},{"package":{"name":"activejob","ecosystem":"RubyGems","purl":"pkg:gem/activejob"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.0.7.1"}]}],"versions":["5.0.0","5.0.0.1","5.0.1","5.0.1.rc1","5.0.1.rc2","5.0.2","5.0.2.rc1","5.0.3","5.0.4","5.0.4.rc1","5.0.5","5.0.5.rc1","5.0.5.rc2","5.0.6","5.0.6.rc1","5.0.7"],"database_specific":{"last_known_affected_version_range":"<= 5.0.7.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-q2qw-rmrh-vv42/GHSA-q2qw-rmrh-vv42.json"}},{"package":{"name":"activejob","ecosystem":"RubyGems","purl":"pkg:gem/activejob"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.1.0"},{"fixed":"5.1.6.1"}]}],"versions":["5.1.0","5.1.1","5.1.2","5.1.2.rc1","5.1.3","5.1.3.rc1","5.1.3.rc2","5.1.3.rc3","5.1.4","5.1.4.rc1","5.1.5","5.1.5.rc1","5.1.6"],"database_specific":{"last_known_affected_version_range":"<= 5.1.6.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-q2qw-rmrh-vv42/GHSA-q2qw-rmrh-vv42.json"}},{"package":{"name":"activejob","ecosystem":"RubyGems","purl":"pkg:gem/activejob"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.2.0"},{"fixed":"5.2.1.1"}]}],"versions":["5.2.0","5.2.1","5.2.1.rc1"],"database_specific":{"last_known_affected_version_range":"<= 5.2.1.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-q2qw-rmrh-vv42/GHSA-q2qw-rmrh-vv42.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-16476"},{"type":"WEB","url":"https://github.com/rails/rails/commit/970b0d754be7c71a760d9b807eea32297fd838e3"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:0600"},{"type":"PACKAGE","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activejob/CVE-2018-16476.yml"},{"type":"WEB","url":"https://groups.google.com/d/msg/rubyonrails-security/FL4dSdzr2zw/zjKVhF4qBAAJ"},{"type":"WEB","url":"https://groups.google.com/forum/#!topic/rubyonrails-security/FL4dSdzr2zw"},{"type":"WEB","url":"https://weblog.rubyonrails.org/2018/11/27/Rails-4-2-5-0-5-1-5-2-have-been-released"}],"database_specific":{"cwe_ids":["CWE-284","CWE-502"],"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:50:29Z","nvd_published_at":"2018-11-30T19:29:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}