Description
In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially private data (that belongs to another user) by making CSV export requests at certain specific times.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-356j-hg45-x525 | Potential CSV export data leak |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T22:16:46.803Z
Reserved: 2023-12-10T00:00:00.000Z
Link: CVE-2023-50448
No data.
Status : Modified
Published: 2023-12-28T23:15:43.500
Modified: 2024-11-21T08:37:01.203
Link: CVE-2023-50448
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA