CVE-2020-8163
CVE-2020-8163
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
Affected products
n/a · https://github.com/rails/railspublic PoCs found — 5
githubgithub.com/lucasamorimca/CVE-2020-8163★ 61githubgithub.com/h4ms1k/CVE-2020-8163★ 4githubgithub.com/RedBinaryRabbit/CVE-2020-8163★ 1cve_referencepacketstormsecurity.com/files/158604/Ruby-On-Rails-5.0.1-Remote-Code-Execution.htmlunverifiedexploitdbwww.exploit-db.com/exploits/48716unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →