A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have.
{ "last_known_affected_version_range": "<= 5.0.7.0" }
{ "last_known_affected_version_range": "<= 5.1.6.0" }
{ "last_known_affected_version_range": "<= 5.2.1.0" }