vulnerability
Ruby on Rails: Deserialization of Untrusted Data (CVE-2020-8165)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
8 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | Jun 19, 2020 | Jun 26, 2020 | May 12, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Jun 19, 2020
Added
Jun 26, 2020
Modified
May 12, 2025
Description
A deserialization of untrusted data vulnernerability exists in rails
Solution(s)
ruby-on-rails-upgrade-5_2_4_3ruby-on-rails-upgrade-6_0_3_1
References
- CVE-2020-8165
- https://attackerkb.com/topics/CVE-2020-8165
- URL-http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00031.html
- URL-http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00034.html
- URL-https://groups.google.com/g/rubyonrails-security/c/bv6fW4S0Y1c
- URL-https://hackerone.com/reports/413388
- URL-https://lists.debian.org/debian-lts-announce/2020/06/msg00022.html
- URL-https://lists.debian.org/debian-lts-announce/2020/07/msg00013.html
- URL-https://security.netapp.com/advisory/ntap-20250509-0002/
- URL-https://weblog.rubyonrails.org/2020/5/18/Rails-5-2-4-3-and-6-0-3-1-have-been-released/
- URL-https://www.debian.org/security/2020/dsa-4766

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.