RubySec

Providing security resources for the Ruby community

GHSA-mpwp-4h2m-765c (activejob): Active Job - Object injection security vulnerability if Global IDs

ADVISORIES

GEM

activejob

FRAMEWORK

Ruby on Rails

PATCHED VERSIONS

  • >= 4.2.0.beta2

DESCRIPTION

Active Job vulnerability: An Active Job bug allowed String arguments to be deserialized as if they were Global IDs, an object injection security vulnerability.

  • In release post: "Active Job vulnerability: We also fixed an Active Job bug that allowed String arguments to be deserialized as if they were Global IDs, an object injection security vulnerability.

RELATED