Lucene search

K
osvGoogleOSV:GHSA-Q2QW-RMRH-VV42
HistoryDec 05, 2018 - 5:24 p.m.

Improper Access Control in activejob

2018-12-0517:24:27
Google
osv.dev
6

0.002 Low

EPSS

Percentile

52.2%

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have.