cbcvebase.
CVE-2020-8165
published 2020-06-19

CVE-2020-8165: A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects…

PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
45.73%
98.7th percentile
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianrails< rails 2:5.2.4.3+dfsg-1 (bookworm)rails 2:5.2.4.3+dfsg-1 (bookworm)
httpsgithub.com_rails_rails
opensuseleap
opensuseleap
rubyonrailsrails< 5.2.4.35.2.4.3
rubyonrailsrails>= 0 < 2:5.2.4.3+dfsg-12:5.2.4.3+dfsg-1
rubyonrailsrails>= 0 < 2:5.2.4.3+dfsg-12:5.2.4.3+dfsg-1
rubyonrailsrails>= 0 < 2:5.2.4.3+dfsg-12:5.2.4.3+dfsg-1
rubyonrailsrails>= 0 < 2:5.2.4.3+dfsg-12:5.2.4.3+dfsg-1
rubyonrailsrails>= 6.0.0 < 6.0.3.16.0.3.1

Detection & IOCsextracted from sources · hover to see the quote

  • Audit application code for any cache write calls that combine user-controlled input with `raw: true` in MemCacheStore or RedisCacheStore — these are the exploitable call sites.
  • Patch commits for Rails 6.0.3.1 and 5.2.4.3 can be used as reference diffs to build detection rules or confirm patched state.
  • ·Red Hat Gluster Storage 3 ships the affected rubygem-activesupport but does NOT use the `raw` option when storing untrusted user input, reducing practical exploitability in that product.
  • ·Red Hat Satellite uses RedisCacheStore with the affected gem, but unmarshalling of user-provided objects is handled safely in product code, so it is not considered vulnerable.
  • ·OpenShift Container Platform 3.11 ships rubygem-activesupport in the logging-fluentd container for rubygem-kubeclient, but kubeclient only uses the inflector portion of activesupport and does NOT invoke the vulnerable cache store class.
  • ·No practical mitigation short of patching has been identified; upgrading to rails >= 5.2.4.3 or >= 6.0.3.1 is the only effective remediation.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.