CVE-2020-8162

CVE-2020-8162

Vendor N/A
Product https://github.com/rails/rails
Weakness CWE-602 · Client-side enforcement
Published June 19, 2020
Last update August 4, 2024

CVSS base score

What the vulnerability does

01Description

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

Key dates

02Disclosure timeline

June 19, 2020 CVE published
August 4, 2024 Record updated