Back to search
CVE-2020-8165
Published: Jun 19, 2020
Modified: May 9, 2025
PUBLISHED
Description
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
| Vendor | Product | Versions |
|---|---|---|
n/a | https://github.com/rails/rails | affected Fixed in 5.2.4.3, 6.0.3.1 |
Weaknesses (CWE)
References
https://hackerone.com/reports/413388
x_refsource_MISC
https://groups.google.com/g/rubyonrails-security/c/bv6fW4S0Y1c
x_refsource_MISC
[debian-lts-announce] 20200619 [SECURITY] [DLA 2251-1] rails security update
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20200720 [SECURITY] [DLA 2282-1] rails security update
mailing-list
x_refsource_MLIST
DSA-4766
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2020:1677
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:1679
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now