← back
CVE-2020-8163

CVE-2020-8163

EPSS 83.1%CWE-94
Vexday Risk Score
45Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS EPSS 83.1%KEV nãoPoC públicaPatch
Lifecycle
19 Jun 2020Public PoC
02 Jul 2020Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →