Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8185

Опубликовано: 17 июн. 2020
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.

Отчет

Red Hat Satellite and Red Hat CloudForms do not ship vulnerable versions of RubyGem Rails hence not affected to the flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5cfme-gemsetNot affected
Red Hat Satellite 6tfm-ror52-rubygem-railsNot affected
Red Hat Satellite 6.9 for RHEL 7ansible-collection-redhat-satelliteFixedRHSA-2021:131321.04.2021
Red Hat Satellite 6.9 for RHEL 7ansiblerole-foreman_scap_clientFixedRHSA-2021:131321.04.2021
Red Hat Satellite 6.9 for RHEL 7ansiblerole-insights-clientFixedRHSA-2021:131321.04.2021
Red Hat Satellite 6.9 for RHEL 7ansiblerole-satellite-receptor-installerFixedRHSA-2021:131321.04.2021
Red Hat Satellite 6.9 for RHEL 7ansible-runnerFixedRHSA-2021:131321.04.2021
Red Hat Satellite 6.9 for RHEL 7candlepinFixedRHSA-2021:131321.04.2021
Red Hat Satellite 6.9 for RHEL 7createrepo_cFixedRHSA-2021:131321.04.2021
Red Hat Satellite 6.9 for RHEL 7foremanFixedRHSA-2021:131321.04.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-250
https://bugzilla.redhat.com/show_bug.cgi?id=1852380rubygem-rails: untrusted users able to run pending migrations in production

EPSS

Процентиль: 77%
0.01071
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 5 лет назад

A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.

CVSS3: 6.5
nvd
около 5 лет назад

A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.

CVSS3: 6.5
debian
около 5 лет назад

A denial of service vulnerability exists in Rails <6.0.3.2 that allowe ...

CVSS3: 6.5
github
около 5 лет назад

Untrusted users can run pending migrations in production in Rails

CVSS3: 7.5
redos
25 дней назад

Множественные уязвимости rubygem-actionpack

EPSS

Процентиль: 77%
0.01071
Низкий

7.1 High

CVSS3