CVE-2023-50448
28.12.2023, 23:15
In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially private data (that belongs to another user) by making CSV export requests at certain specific times.Enginsight
Vendor | Product | Version |
---|---|---|
activeadmin | activeadmin | 𝑥 < 2.12.0 |
𝑥
= Vulnerable software versions