CVE-2020-8163
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the locals argument of a render call to...
- Published
- Jul 2, 2020
- Updated
- Aug 4, 2024
- Assigning CNA
- hackerone
- Evidence observed
- Jul 26, 2020
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
Sources
4- CVE-2020-8163Exploit
Docker-based lab environment and exploit script for CVE-2020-8163, a blind remote code execution vulnerability in Rails versions before 5.0.1 and 4.2.11.2.
- CVE-2020-8163Exploit
CVE-2020-8163 - Remote code execution of user-provided local names in Rails
- CVE-2020-8163Exploit
This is a exploit code for CVE-2020-8163
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.