Количество 8
Количество 8
CVE-2018-16476
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.
CVE-2018-16476
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.
CVE-2018-16476
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.
CVE-2018-16476
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 ...
openSUSE-SU-2018:4041-1
Security update for rubygem-activejob-5_1
SUSE-SU-2018:3996-1
Security update for rubygem-activejob-5_1
GHSA-q2qw-rmrh-vv42
Improper Access Control in activejob
BDU:2020-00686
Уязвимость функции MyJob.perform_later программной платформы Ruby on Rails, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-16476 A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1. | CVSS3: 7.5 | 1% Низкий | около 7 лет назад | |
CVE-2018-16476 A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1. | CVSS3: 4.3 | 1% Низкий | около 7 лет назад | |
CVE-2018-16476 A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1. | CVSS3: 7.5 | 1% Низкий | около 7 лет назад | |
CVE-2018-16476 A Broken Access Control vulnerability in Active Job versions >= 4.2.0 ... | CVSS3: 7.5 | 1% Низкий | около 7 лет назад | |
openSUSE-SU-2018:4041-1 Security update for rubygem-activejob-5_1 | 1% Низкий | около 7 лет назад | ||
SUSE-SU-2018:3996-1 Security update for rubygem-activejob-5_1 | 1% Низкий | около 7 лет назад | ||
GHSA-q2qw-rmrh-vv42 Improper Access Control in activejob | CVSS3: 7.5 | 1% Низкий | около 7 лет назад | |
BDU:2020-00686 Уязвимость функции MyJob.perform_later программной платформы Ruby on Rails, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным | CVSS3: 7.5 | 1% Низкий | около 7 лет назад |
Уязвимостей на страницу