Логотип exploitDog
bind:CVE-2018-16476
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-16476

Количество 8

Количество 8

ubuntu логотип

CVE-2018-16476

около 7 лет назад

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-16476

около 7 лет назад

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-16476

около 7 лет назад

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-16476

около 7 лет назад

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:4041-1

около 7 лет назад

Security update for rubygem-activejob-5_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3996-1

около 7 лет назад

Security update for rubygem-activejob-5_1

EPSS: Низкий
github логотип

GHSA-q2qw-rmrh-vv42

около 7 лет назад

Improper Access Control in activejob

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2020-00686

около 7 лет назад

Уязвимость функции MyJob.perform_later программной платформы Ruby on Rails, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-16476

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.

CVSS3: 7.5
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2018-16476

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.

CVSS3: 4.3
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-16476

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.

CVSS3: 7.5
1%
Низкий
около 7 лет назад
debian логотип
CVE-2018-16476

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 ...

CVSS3: 7.5
1%
Низкий
около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:4041-1

Security update for rubygem-activejob-5_1

1%
Низкий
около 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:3996-1

Security update for rubygem-activejob-5_1

1%
Низкий
около 7 лет назад
github логотип
GHSA-q2qw-rmrh-vv42

Improper Access Control in activejob

CVSS3: 7.5
1%
Низкий
около 7 лет назад
fstec логотип
BDU:2020-00686

Уязвимость функции MyJob.perform_later программной платформы Ruby on Rails, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным

CVSS3: 7.5
1%
Низкий
около 7 лет назад

Уязвимостей на страницу