A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade rubygem-actionpack60 | Jun 23, 2020 | Jun 22, 2020 |
| Ruby_on_rails | — | Upgrade to the latest version of Ruby on Rails | Jul 10, 2020 | Jul 2, 2020 |
| Suse | — | Upgrade rmt-serverUpgrade rmt-server-configUpgrade rmt-server-pubcloud | Nov 5, 2020 | Jun 17, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub