CVE-2020-8159: Path Traversal
There is a vulnerability in actionpackpage-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-8159.
What is the title of the vulnerability?
The title of the vulnerability is 'There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server.'
What is the description of the vulnerability?
The description of the vulnerability is: 'There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.'
What software is affected by this vulnerability?
The affected software are Rubyonrails Actionpack Page-caching gem < v1.2.1 and Debian Debian Linux 9.0.
What is the severity of CVE-2020-8159?
The severity of CVE-2020-8159 is critical with a score of 9.8.