CVE-2018-16476

NameCVE-2018-16476
DescriptionA Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
Debian Bugs914847

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rails (PTS)jessie (security), jessie2:4.1.8-1+deb8u4fixed
stretch2:4.2.7.1-1vulnerable
buster, sid2:4.2.10-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
railssource(unstable)(unfixed)914847
railssourcejessie(not affected)

Notes

[jessie] - rails <not-affected> (only affects >= 4.2.0)
https://www.openwall.com/lists/oss-security/2018/11/27/4

Search for package or bug name: Reporting problems