VDB

CVE-2020-8162

CVE-2020-8162 PUBLISHED

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

EPSS 1.55% · 81.8th percentile

Risk Scores

EPSS Score
1.55%
81.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSrails*, 2:4.2.10-0ubuntu4, 2:4.2.10-0ubuntu4+esm2
Ubuntu:Pro:16.04:LTSrails0, *, *
Ubuntu:Pro:20.04:LTSrails0, *, *

Exploit Intelligence

…and 86 more exploits

Timeline

  • CVE Published
  • May 18, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 11, 2023 EPSS Score
  • May 13, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›