{ "id": "CVE-2023-50448", "sourceIdentifier": "cve@mitre.org", "published": "2023-12-28T23:15:43.500", "lastModified": "2023-12-28T23:15:43.500", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "In ActiveAdmin (aka Active Admin) before 2.12.0, a concurrency issue allows a malicious actor to access potentially private data (that belongs to another user) by making CSV export requests at certain specific times." } ], "metrics": {}, "references": [ { "url": "https://github.com/activeadmin/activeadmin/pull/7336", "source": "cve@mitre.org" }, { "url": "https://github.com/activeadmin/activeadmin/security/advisories/GHSA-356j-hg45-x525", "source": "cve@mitre.org" } ] }