First published: Tue May 12 2020(Updated: )
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rubyonrails Active Resource | <5.1.1 | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8151 is a vulnerability that allows an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information in Active Resource <v5.1.1.
The severity of CVE-2020-8151 is high with a CVSS score of 7.5.
Rubyonrails Active Resource <v5.1.1 and Fedoraproject Fedora 33 are affected by CVE-2020-8151.
An attacker can exploit CVE-2020-8151 by creating specially crafted requests to gain unauthorized access to data and potentially leak information.
Yes, you can find more information about CVE-2020-8151 at the following references: [link1](https://groups.google.com/forum/#!topic/rubyonrails-security/pktoF4VmiM8), [link2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P7B7A4H22DZ522HLDS3JX3NX2CXIOZSR/)