Code Injection in ActionView - CVE-2020-8163
Published: May 26, 2020 / Updated: July 1, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote attacker can control the "locals" argument of a "render" call and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2020-8163
Links to Public Exploits and PoC-codes
- Exploit #6502 - CVE-2020-8163 (CVE-2020-8163 - Remote code execution of user-provided local names in Rails) (July 1, 2021)
- Exploit #5690 - Rails 5.0.1 - Remote Code Execution (June 17, 2021)
- Exploit #3532 - CVE-2020-8163 (Enviroment and exploit to rce test) (July 20, 2020)
- Exploit #3465 - CVE-2020-8163 (CVE-2020-8163 - Remote code execution of user-provided local names in Rails) (July 15, 2020)