A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade rails | Jun 22, 2020 | Jun 19, 2020 |
| Freebsd | — | Upgrade rubygem-actionview60Upgrade rubygem-activesupport60Upgrade rubygem-activestorage60Upgrade rubygem-actionpack52Upgrade rubygem-actionpack60Upgrade rubygem-activesupport52Upgrade rubygem-activestorage52Upgrade rubygem-actionview52 | May 20, 2020 | May 19, 2020 |
| Ruby_on_rails | — | Upgrade to the latest version of Ruby on Rails | Jun 26, 2020 | Jun 19, 2020 |
| Suse | — | Upgrade ruby2.5-rubygem-activesupport-doc-5_1Upgrade ruby2.5-rubygem-activesupport-5_1Upgrade rmt-server-pubcloudUpgrade rmt-serverUpgrade rmt-server-config | Oct 20, 2020 | May 18, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub