CVE-2018-16476 on Ubuntu 14.04 LTS (trusty) - medium.
Description:
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have.