CVE-2020-8163
A code injection vulnerability in Rails would allow an attacker
who controlled the `locals` argument of a `render` call to perform
a RCE.
CVE-2020-8164
A deserialization of untrusted data vulnerability exists in rails
which can allow an attacker to supply information can be
inadvertently leaked from Strong Parameters.
CVE-2020-8165
A deserialization of untrusted data vulnernerability exists in
rails that can allow an attacker to unmarshal user-provided objects
in MemCacheStore and RedisCacheStore potentially resulting in an
RCE.
For Debian 9 stretch, these problems have been fixed in version
2:4.2.7.1-1+deb9u3.
We recommend that you upgrade your rails packages.
For the detailed security status of rails please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/rails
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
Get the latest Linux and open source security news straight to your inbox.