vendor:
Rails
by:
Lucas Amorim
8.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Rails
Affected Version From: Rails < 5.0.1
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2020-8163
CPE: a:rubyonrails:rubyonrails
Tags: cve,cve2020,rails,rce,hackerone
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Nuclei Metadata: {'max-request': 1, 'vendor': 'rubyonrails', 'product': 'rails'}
Platforms Tested: Linux, OSx
2020
Rails 5.0.1 – Remote Code Execution
Remote code execution of user-provided local names in Rails < 5.0.1
Mitigation:
Upgrade to Rails 5.0.1 or newer version