Vulnerability Intelligence Report
CVE-2020-8165
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:45.73%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-502 ↗Deserialization of Untrusted Data (CWE-502)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| rubyonrails | rails | all |
| debian | debian_linux | 8.0, 9.0, 10.0 |
| opensuse | leap | 15.1, 15.2 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
45.732%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | HackerOne · Bug Bounty Provider · USA |
| Reserved | 2020-01-28T00:00:00 |
| Published | 2020-06-19T17:05:30 |
| Last Updated | 2025-05-09T20:03:28 |
Community Chatter & Buzz