Количество 8
Количество 8
BDU:2020-00686
Уязвимость функции MyJob.perform_later программной платформы Ruby on Rails, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным
CVE-2018-16476
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.
CVE-2018-16476
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.
CVE-2018-16476
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.
CVE-2018-16476
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 ...
openSUSE-SU-2018:4041-1
Security update for rubygem-activejob-5_1
SUSE-SU-2018:3996-1
Security update for rubygem-activejob-5_1
GHSA-q2qw-rmrh-vv42
Improper Access Control in activejob
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2020-00686 Уязвимость функции MyJob.perform_later программной платформы Ruby on Rails, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным | CVSS3: 7.5 | 3% Низкий | больше 7 лет назад | |
CVE-2018-16476 A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1. | CVSS3: 7.5 | 3% Низкий | больше 7 лет назад | |
CVE-2018-16476 A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1. | CVSS3: 4.3 | 3% Низкий | больше 7 лет назад | |
CVE-2018-16476 A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1. | CVSS3: 7.5 | 3% Низкий | больше 7 лет назад | |
CVE-2018-16476 A Broken Access Control vulnerability in Active Job versions >= 4.2.0 ... | CVSS3: 7.5 | 3% Низкий | больше 7 лет назад | |
openSUSE-SU-2018:4041-1 Security update for rubygem-activejob-5_1 | 3% Низкий | больше 7 лет назад | ||
SUSE-SU-2018:3996-1 Security update for rubygem-activejob-5_1 | 3% Низкий | больше 7 лет назад | ||
GHSA-q2qw-rmrh-vv42 Improper Access Control in activejob | CVSS3: 7.5 | 3% Низкий | больше 7 лет назад |
Уязвимостей на страницу