vulnerability
Ruby on Rails: Deserialization of Untrusted Data (CVE-2020-8164)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:N/AC:L/Au:N/C:P/I:N/A:N) | 06/19/2020 | 06/29/2020 | 11/26/2024 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
06/19/2020
Added
06/29/2020
Modified
11/26/2024
Description
A deserialization of untrusted data vulnerability exists in rails
Solution(s)
ruby-on-rails-upgrade-5_2_4_3ruby-on-rails-upgrade-6_0_3_1
References
- CVE-2020-8164
- https://attackerkb.com/topics/CVE-2020-8164
- URL-http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00089.html
- URL-http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00093.html
- URL-http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00107.html
- URL-https://groups.google.com/g/rubyonrails-security/c/f6ioe4sdpbY
- URL-https://hackerone.com/reports/292797
- URL-https://lists.debian.org/debian-lts-announce/2020/06/msg00022.html
- URL-https://lists.debian.org/debian-lts-announce/2020/07/msg00013.html
- URL-https://www.debian.org/security/2020/dsa-4766

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.