CVE-2020-8162: Malicious File Upload
Published Jun 19, 2020
·Updated
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
Affected Software
4 affected componentsFixes available
debian/rails
2:5.2.2.1+dfsg-1+deb10u32:5.2.2.1+dfsg-1+deb10u52:6.0.3.7+dfsg-2+deb11u22:6.1.7.3+dfsg-12:6.1.7.3+dfsg-2
rubyonrails Rails<5.2.4.2
rubyonrails Rails>=6.0.0<6.0.3.1
Debian Debian Linux=10.0
Remediation
Event History
Jun 19, 2020
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-8162?
CVE-2020-8162 is a client-side enforcement of server-side security vulnerability in Rails < 5.2.4.2 and Rails < 6.0.3.1 ActiveStorage's S3 adapter.
2
How does CVE-2020-8162 work?
CVE-2020-8162 allows an end user to modify the Content-Length of a direct file upload, bypassing upload limits.
3
What is the severity of CVE-2020-8162?
The severity of CVE-2020-8162 is not specified.
4
Which software versions are affected by CVE-2020-8162?
CVE-2020-8162 affects Rails < 5.2.4.2 and Rails < 6.0.3.1.
5
How can I fix CVE-2020-8162?
To fix CVE-2020-8162, you should update Rails to version 5.2.4.3 or 6.0.3.1 or later.