VDB
Sign up
MEDIUM

GHSA-mpwp-4h2m-765c

Active Job - Object injection security vulnerability

Quick fix

GHSA-mpwp-4h2m-765c — activejob: upgrade to the fixed version with the command below.

bundle update activejob

Details

Active Job vulnerability: An Active Job bug allowed String arguments to be deserialized as if they were Global IDs, an object injection security vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activejob
Introduced in: 0Fixed in: 4.2.0.beta2
Fixbundle update activejob

References