Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-8162

Опубликовано: 19 июн. 2020
Источник: debian

Описание

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2:5.2.4.3+dfsg-1package
railsnot-affectedstretchpackage
railsnot-affectedjessiepackage

Примечания

  • https://weblog.rubyonrails.org/2020/5/18/Rails-5-2-4-3-and-6-0-3-1-have-been-released

  • https://github.com/rails/rails/commit/e8df5648515a0e8324d3b3c4bdb7bde6802cd8be (5.2)

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

CVSS3: 7.5
redhat
больше 5 лет назад

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

CVSS3: 7.5
nvd
больше 5 лет назад

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

CVSS3: 7.5
github
больше 5 лет назад

Circumvention of file size limits in ActiveStorage

CVSS3: 9.8
fstec
больше 5 лет назад

Уязвимость программной платформы Ruby on Rails, связанная с реализацией функций безопасности на стороне клиента, позволяющая нарушителю выполнить произвольный код