In certain setups with threaded web servers, Audited's use of Thread.current can incorrectly attributed audits to the wrong user.
Fixed in 5.3.3.
In March, @convisoappsec noticed that the library in question had a Race Condition problem, which caused logs to be registered at times with different users than those who performed the genuine actions.
{
"github_reviewed": true,
"cwe_ids": [],
"github_reviewed_at": "2023-05-01T14:00:47Z",
"nvd_published_at": null,
"severity": "LOW"
}