CVE-2020-8163

HIGH8.8EPSS 91.1%

Remote code execution via user-provided local names in ActionView

Published: 7/7/2020Modified: 2/16/2024
Also known as:GHSA-cr3x-7m39-c6jqBIT-rails-2020-8163

Description

The is a code injection vulnerability in versions of Rails prior to 5.0.1 that would allow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (8)