OESA-2021-1145
Dashboard / Vulnerabilities / OESA-2021-1145
Summary: rubygem-rails security update
Details: Ruby on Rails is a full-stack web framework optimized for programmer happiness and sustainable productivity. It encourages beautiful code by favoring convention over configuration. Security Fix(es): A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.(CVE-2020-8165) A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorages S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.(CVE-2020-8162)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1145, https://nvd.nist.gov/vuln/detail/CVE-2020-8165, https://nvd.nist.gov/vuln/detail/CVE-2020-8162
Affected packages
Package
Name: rubygem-rails
Purl: pkg:rpm/openEuler/rubygem-rails&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
