Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Debian LTS: DLA-2282-1 Moderate: Rails Remote Code Execution Threat

debian lts
Calendar Grey July 20, 2020
Dist Debian Esm H88
Recent security flaws within Ruby on Rails, as pointed out by Debian LTS Notice DLA-2282-1, strongly recommend that users update their systems.
Multiple vulnerabilities were found in Ruby on Rails, a MVC ruby-based framework geared for web application development, which could lead to remote code execution and untrusted use...

Summary

CVE-2020-8163

A code injection vulnerability in Rails would allow an attacker
who controlled the `locals` argument of a `render` call to perform
a RCE.

CVE-2020-8164

A deserialization of untrusted data vulnerability exists in rails
which can allow an attacker to supply information can be
inadvertently leaked from Strong Parameters.

CVE-2020-8165

A deserialization of untrusted data vulnernerability exists in
rails that can allow an attacker to unmarshal user-provided objects
in MemCacheStore and RedisCacheStore potentially resulting in an
RCE.

For Debian 9 stretch, these problems have been fixed in version
2:4.2.7.1-1+deb9u3.

We recommend that you upgrade your rails packages.

For the detailed security status of rails please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/rails

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be

Read the Full Advisory


Package: rails
Version: 2:4.2.7.1-1+deb9u3
CVE ID: CVE-2020-8163 CVE-2020-8164 CVE-2020-8165

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here