← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-8163

The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.

Nuclei Template
CVSS Base Score
8.8
HIGH
EPSS Probability:83.08%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-94 ↗Code Injection (CWE-94)

Affected Products & Versions

Vendor Product Affected Versions
rubyonrails rails all
debian debian_linux 9.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
83.085%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHackerOne · Bug Bounty Provider · USA
Reserved2020-01-28T00:00:00
Published2020-07-02T18:35:12
Last Updated2024-08-04T09:48:25

LINK COPIED TO CLIPBOARD