Description
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: High
Availability: None
Affected Packages4 packages
Also affects: Debian Linux 10.0
🔴Vulnerability Details
4CVEListCVE-2020-8162: A client side enforcement of server side security vulnerability exists in rails < 5↗2020-06-19 ▶ OSVCVE-2020-8162: A client side enforcement of server side security vulnerability exists in rails < 5↗2020-06-19 ▶ OSVCircumvention of file size limits in ActiveStorage↗2020-05-26 ▶ GHSACircumvention of file size limits in ActiveStorage↗2020-05-26 ▶ 📋Vendor Advisories
2Red Hatrubygem-activestorage: circumvention of file size limits in ActiveStorage↗2020-05-18 ▶ DebianCVE-2020-8162: rails - A client side enforcement of server side security vulnerability exists in rails ...↗2020 ▶ 💬Community
2BugzillaCVE-2020-8162 rubygem-activestorage: circumvention of file size limits in ActiveStorage↗2020-06-02 ▶ BugzillaCVE-2020-8162 rubygem-activestorage: circumvention of file size limits in ActiveStorage [fedora-all]↗2020-06-02 ▶