CVE-2020-8163 is a critical code injection vulnerability affecting Ruby on Rails versions prior to 5.0.1, specifically impacting Debian Linux and Rails installations. An authenticated attacker could exploit this flaw by manipulating the 'locals' argument in a 'render' call to achieve Remote Code Execution (RCE). With a CVSS score of 8.8 (HIGH) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its low attack complexity and severe potential impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, public exploit code is available via ExploitDB and Nuclei templates, though there is minimal community discussion or media coverage surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.1CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remote code execution via user-provided local names in ActionView
Jul 7, 2020Rails 5.2.4.3 and 6.0.3.1 have been released
May 18, 2020Rails 4.2.11.3 has been released
May 16, 2020Rails 4.2.11.3 has been released
May 16, 2020Rails 4.2.11.3 has been released
May 16, 2020Rails 4.2.11.3 has been released
May 16, 2020Rails 4.2.11.2 has been released
May 15, 2020rubygem-rails: potential remote code execution of user-provided local names
May 15, 2020Rails 4.2.11.2 has been released
May 15, 2020Rails 4.2.11.2 has been released
May 15, 2020Rails 4.2.11.2 has been released
May 15, 2020Rails 4.2.11.2 has been released
May 15, 2020