CVE-2020-8163

unknown
Published 2020-05-15 · Modified 2024-02-16
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
1.0

Description

The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.

Predictions

Exploit likelihood
65%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-8163

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-8163.html

Exploits

Exploit-DB

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed2:5.2.0+dfsg-2
debian debianbullseyefixed2:5.2.0+dfsg-2
debian debianforkyfixed2:5.2.0+dfsg-2
debian debiansidfixed2:5.2.0+dfsg-2
debian debiantrixiefixed2:5.2.0+dfsg-2

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsactionview<>= 4.2.11.2>= 4.2.11.2
ruby RubyGemsactionview<4.2.11.34.2.11.3

References

Verify integrity in audit chain (admin only). AS-IS.