Active Storage是一款用于将文件上传到多种云存储服务,并将文件附加到Active Record对象的插件。 Active Storage 5.2.0及之前版本(用于Google Cloud Storage和Disk服务)中存在访问控制错误漏洞。该漏洞源于网络系统或产品未正确限制来自未授权角色的资源访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | https://github.com/rails/rails | 5.2.0 and later and before 5.2.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-19763 | libsixel 缓冲区错误漏洞 | |
| CVE-2018-16476 | Active Job 代码问题漏洞 | |
| CVE-2018-19290 | Budabot 安全漏洞 | |
| CVE-2018-18987 | INVT Electric VT-Designer 安全漏洞 | |
| CVE-2018-18983 | INVT Electric VT-Designer 缓冲区错误漏洞 | |
| CVE-2018-18860 | SwitchVPN for macOS 权限许可和访问控制问题漏洞 | |
| CVE-2018-15835 | Android 信息泄露漏洞 | |
| CVE-2018-3948 | TP-Link TL-R600VPN 输入验证错误漏洞 | |
| CVE-2018-19777 | Artifex MuPDF 安全漏洞 | |
| CVE-2018-19755 | Netwide Assembler 安全漏洞 | |
| CVE-2018-19762 | libsixel 缓冲区错误漏洞 | |
| CVE-2018-19761 | libsixel 安全漏洞 | |
| CVE-2018-19760 | libConfuse 安全漏洞 | |
| CVE-2018-19759 | libsixel 缓冲区错误漏洞 | |
| CVE-2018-19758 | libsndfile 缓冲区错误漏洞 | |
| CVE-2018-19757 | libsixel 安全漏洞 | |
| CVE-2018-19756 | libsixel 缓冲区错误漏洞 |
No comments yet