There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2020-05-12T13:01:43
Updated: 2024-08-04T09:48:25.823Z
Reserved: 2020-01-28T00:00:00
Link: CVE-2020-8159
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-05-12T13:15:13.250
Modified: 2023-11-07T03:26:17.570
Link: CVE-2020-8159
Redhat
No data.