First published: Thu Jul 02 2020(Updated: )
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rubyonrails Rails | <5.0.1 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-8163 is high with a severity value of 8.8.
The affected software for CVE-2020-8163 includes versions of Ruby on Rails prior to 5.0.1 and Debian Linux 9.0.
An attacker can exploit CVE-2020-8163 by controlling the 'locals' argument of a 'render' call to perform a remote code execution.
Yes, you can find references for CVE-2020-8163 at the following URLs: [http://packetstormsecurity.com/files/158604/Ruby-On-Rails-5.0.1-Remote-Code-Execution.html](http://packetstormsecurity.com/files/158604/Ruby-On-Rails-5.0.1-Remote-Code-Execution.html), [https://groups.google.com/g/rubyonrails-security/c/hWuKcHyoKh0](https://groups.google.com/g/rubyonrails-security/c/hWuKcHyoKh0), [https://hackerone.com/reports/304805](https://hackerone.com/reports/304805).
Yes, the Common Weakness Enumeration (CWE) associated with CVE-2020-8163 is CWE-94.