CVE-2018-16476
Improper Access Control in activejob
7.5
HIGH
CVSS 3.1
EPSS 2.6%
描述
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.
如何修補 CVE-2018-16476
要修補 CVE-2018-16476,請將受影響套件升級到下列已修補版本。
- —升級至 2:5.2.2+dfsg-1 或更新版本
- —升級至 4.2.11 或更新版本
CVE-2018-16476 正在被利用嗎?
低 — EPSS 為 2.6%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2:5.2.2+dfsg-1
- >= 4.2.0, < 4.2.11
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |