CVE-2020-8162
published 2020-06-19CVE-2020-8162: A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
3.06%
86.2th percentile
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | rails | < rails 2:5.2.4.3+dfsg-1 (bookworm) | rails 2:5.2.4.3+dfsg-1 (bookworm) |
| https | github.com_rails_rails | — | — |
| rails | activestorage | >= 5.0.0 < 5.2.4.3 | 5.2.4.3 |
| rails | activestorage | >= 6.0.0 < 6.0.3.1 | 6.0.3.1 |
| rubyonrails | rails | < 5.2.4.2 | 5.2.4.2 |
| rubyonrails | rails | >= 0 < 2:5.2.4.3+dfsg-1 | 2:5.2.4.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:5.2.4.3+dfsg-1 | 2:5.2.4.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:5.2.4.3+dfsg-1 | 2:5.2.4.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:5.2.4.3+dfsg-1 | 2:5.2.4.3+dfsg-1 |
| rubyonrails | rails | >= 6.0.0 < 6.0.3.1 | 6.0.3.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-activestorage: circumvention of file size limits in ActiveStorage
vendor_redhat·2020-05-18·CVSS 7.5
CVE-2020-8162 [HIGH] CWE-20 rubygem-activestorage: circumvention of file size limits in ActiveStorage
rubygem-activestorage: circumvention of file size limits in ActiveStorage
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
A flaw was found in rubygem-activestorage. The ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user. The highest threat from this vulnerability is to data integrity.
Package: cfme-gemset (CloudForms Management Engine 5) - Will not fix
Debian
CVE-2020-8162: rails - A client side enforcement of server side security vulnerability exists in rails ...
vendor_debian·2020·CVSS 7.5
CVE-2020-8162 [HIGH] CVE-2020-8162: rails - A client side enforcement of server side security vulnerability exists in rails ...
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
Scope: local
bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1)
bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1)
forky: resolved (fixed in 2:5.2.4.3+dfsg-1)
sid: resolved (fixed in 2:5.2.4.3+dfsg-1)
trixie: resolved (fixed in 2:5.2.4.3+dfsg-1)
OSV
CVE-2020-8162: A client side enforcement of server side security vulnerability exists in rails < 5
osv·2020-06-19·CVSS 7.5
CVE-2020-8162 [HIGH] CVE-2020-8162: A client side enforcement of server side security vulnerability exists in rails < 5
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
OSV
Circumvention of file size limits in ActiveStorage
osv·2020-05-26
CVE-2020-8162 [HIGH] Circumvention of file size limits in ActiveStorage
Circumvention of file size limits in ActiveStorage
There is a vulnerability in ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user.
Versions Affected: rails = 5.2.4.3, rails >= 6.0.3.1
Impact
Utilizing this vulnerability, an attacker can control the Content-Length of an S3 direct upload URL without receiving a new signature from the server. This could be used to bypass controls in place on the server to limit upload size.
Workarounds
This is a low-severity security issue. As such, no workaround is necessarily until such time as the application can be upgraded.
GHSA
Circumvention of file size limits in ActiveStorage
ghsa·2020-05-26
CVE-2020-8162 [HIGH] CWE-434 Circumvention of file size limits in ActiveStorage
Circumvention of file size limits in ActiveStorage
There is a vulnerability in ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user.
Versions Affected: rails = 5.2.4.3, rails >= 6.0.3.1
Impact
Utilizing this vulnerability, an attacker can control the Content-Length of an S3 direct upload URL without receiving a new signature from the server. This could be used to bypass controls in place on the server to limit upload size.
Workarounds
This is a low-severity security issue. As such, no workaround is necessarily until such time as the application can be upgraded.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8162 rubygem-activestorage: circumvention of file size limits in ActiveStorage
bugzilla·2020-06-02·CVSS 7.5
CVE-2020-8162 [HIGH] CVE-2020-8162 rubygem-activestorage: circumvention of file size limits in ActiveStorage
CVE-2020-8162 rubygem-activestorage: circumvention of file size limits in ActiveStorage
There is a vulnerability in ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user.
Reference:
https://groups.google.com/forum/#!msg/rubyonrails-security/PjU3946mreQ/Dn-6uLbAAQAJ
Discussion:
Created rubygem-activestorage tracking bugs for this issue:
Affects: fedora-all [bug 1843006]
---
HackerOne Report: https://hackerone.com/reports/789579
GitHub Commit: https://github.com/rails/rails/commit/c0ab9a7d29b84a6ccb1ffa3e8ca1ce61f7a9fbb8
---
External References:
https://groups.google.com/forum/#!msg/rubyonrails-security/PjU3946mreQ/Dn-6uLbAAQAJ
Bugzilla
CVE-2020-8162 rubygem-activestorage: circumvention of file size limits in ActiveStorage [fedora-all]
bugzilla·2020-06-02·CVSS 7.5
CVE-2020-8162 [HIGH] CVE-2020-8162 rubygem-activestorage: circumvention of file size limits in ActiveStorage [fedora-all]
CVE-2020-8162 rubygem-activestorage: circumvention of file size limits in ActiveStorage [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
2020-06-19
Published