Description
A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6Attack Vector: Network
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: High
Affected Packages3 packages
Also affects: Fedora 33
🔴Vulnerability Details
4CVEListCVE-2020-8185: A denial of service vulnerability exists in Rails <6↗2020-07-02 ▶ OSVCVE-2020-8185: A denial of service vulnerability exists in Rails <6↗2020-07-02 ▶ OSVUntrusted users can run pending migrations in production in Rails↗2020-06-24 ▶ GHSAUntrusted users can run pending migrations in production in Rails↗2020-06-24 ▶ 📋Vendor Advisories
2Red Hatrubygem-rails: untrusted users able to run pending migrations in production↗2020-06-17 ▶ DebianCVE-2020-8185: rails - A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untru...↗2020 ▶ 💬Community
2BugzillaCVE-2020-8185 rubygem-rails: untrusted users able to run pending migrations in production↗2020-06-30 ▶ BugzillaCVE-2020-8185 rubygem-rails: untrusted users able to run pending migrations in production [fedora-all]↗2020-06-30 ▶