CVE-2018-16476 is a Broken Access Control vulnerability in Active Job versions 4.2.0 and later, impacting products like Red Hat CloudForms and Ruby on Rails. An attacker can manipulate user input to trigger GlobalID deserialization, leading to unauthorized information disclosure. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with no user interaction, potentially granting access to sensitive data. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community and media attention, including a mention in a GitLab security release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.2.0, < 4.2.11CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.0.7.1CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
>= 5.1.0, < 5.1.6.1CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
>= 5.2.0, < 5.2.1.1CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
4.6CPE matchmatch criteria | cpe:2.3:a:redhat:cloudforms:4.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.