rubyonrails rails CVE-2020-8162 in Ruby on Rails and Debian Products
Published on June 19, 2020

product logo product logo
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

Vendor Advisory NVD

Weakness Type

Client-Side Enforcement of Server-Side Security

The software is composed of a server that relies on the client to implement a mechanism that is intended to protect the server. When the server relies on protection mechanisms placed on the client side, an attacker can modify the client-side behavior to bypass the protection mechanisms resulting in potentially unexpected interactions between the client and server. The consequences will vary, depending on what the mechanisms are trying to protect.


Products Associated with CVE-2020-8162

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-8162 are published in these products:

 
 

Exploit Probability

EPSS
1.55%
Percentile
81.07%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.