CVE-2020-8164 PUBLISHED

A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.

EPSS 7.39% · 91.7th percentile

Risk Scores

EPSS Score
7.39%
91.7th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSrails0, 2:4.2.9-2, 2:4.2.10-0ubuntu4
Ubuntu:Pro:16.04:LTSrails*, *, 0
Ubuntu:Pro:20.04:LTSrails0, 2:5.2.3+dfsg-3, 2:5.2.3+dfsg-3ubuntu0.1~esm1

Timeline

References

Open in Interactive Console →