CVE-2020-8162 PUBLISHED

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

EPSS 1.55% · 81.3th percentile

Risk Scores

EPSS Score
1.55%
81.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSrails0, 2:4.2.9-2, 2:4.2.9-4
Ubuntu:Pro:16.04:LTSrails2:4.2.6-1ubuntu0.1~esm1, 2:4.2.6-1ubuntu0.1~esm2, 0
Ubuntu:Pro:20.04:LTSrails0, 2:5.2.2.1+dfsg-1ubuntu1, 2:5.2.3+dfsg-3

Timeline

References

Open in Interactive Console →