cbcvebase.
CVE-2020-8163
published 2020-07-02

CVE-2020-8163: The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EXPLOIT
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianrails< rails 2:5.2.0+dfsg-2 (bookworm)rails 2:5.2.0+dfsg-2 (bookworm)
httpsgithub.com_rails_rails
railsactionview>= 0 < 4.2.11.34.2.11.3
rubyonrailsrails< 5.0.15.0.1
rubyonrailsrails>= 0 < 2:5.2.0+dfsg-22:5.2.0+dfsg-2
rubyonrailsrails>= 0 < 2:5.2.0+dfsg-22:5.2.0+dfsg-2
rubyonrailsrails>= 0 < 2:5.2.0+dfsg-22:5.2.0+dfsg-2
rubyonrailsrails>= 0 < 2:5.2.0+dfsg-22:5.2.0+dfsg-2

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH