CVE Database
/

CVE-2020-8165

Back to search

CVE-2020-8165

Published: Jun 19, 2020

Modified: May 9, 2025

PUBLISHED

Description

A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

VendorProductVersions

n/a

https://github.com/rails/rails

affected
Fixed in 5.2.4.3, 6.0.3.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now