CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2020-8165

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1270%
EPSS Percentile5.23th
Published2020年6月19日
Last Modified2025年5月9日

Vulnerability Description

A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

Affected Platforms (CPE)

📦
Rubyonrails

Rails

< 5.2.4.3
📦
Rubyonrails

Rails

>= 6.0.0 and < 6.0.3.1
💻
Debian

Debian Linux

= 8.0
💻
Debian

Debian Linux

= 9.0
💻
Debian

Debian Linux

= 10.0
💻
Opensuse

Leap

= 15.1
💻
Opensuse

Leap

= 15.2

References & Advisories

相關漏洞威脅