CVE-2018-16476: High severity ruby on rails vulnerability
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have.
References: https://groups.google.com/d/msg/rubyonrails-security/FL4dSdzr2zw/zjKVhF4qBAAJ https://weblog.rubyonrails.org/2018/11/27/Rails-4-2-5-0-5-1-5-2-have-been-released/
Other sources
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-16476?
CVE-2018-16476 is a Broken Access Control vulnerability in Active Job versions >= 4.2.0.
How does CVE-2018-16476 affect Ruby on Rails?
CVE-2018-16476 allows an attacker to craft user input that can give them unauthorized access to information in Active Job using GlobalId in Ruby on Rails.
How severe is CVE-2018-16476?
CVE-2018-16476 has a severity rating of 7.5 (High).
How can I fix CVE-2018-16476 in Active Job?
To fix CVE-2018-16476, update to one of the following versions: 4.2.11, 5.0.7.1, 5.1.6.1, or 5.2.1.1.
Where can I find more information about CVE-2018-16476?
You can find more information about CVE-2018-16476 on the following references: [link1], [link2], [link3].