CVE-2018-16476

NameCVE-2018-16476
DescriptionA Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)
Debian Bugs914847

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rails (PTS)jessie (security), jessie2:4.1.8-1+deb8u4fixed
stretch2:4.2.7.1-1vulnerable
buster2:5.2.2+dfsg-1fixed
sid2:5.2.2+dfsg-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
railssource(unstable)2:5.2.2+dfsg-1medium914847
railssourcejessie(not affected)

Notes

[jessie] - rails <not-affected> (only affects >= 4.2.0)
https://www.openwall.com/lists/oss-security/2018/11/27/4

Search for package or bug name: Reporting problems