Security Vulnerability in ActiveStorage S3 Adapter by Rails
CVE-2020-8162
7.5HIGH
Key Information:
- Vendor
Rubyonrails
- Vendor
- CVE Published:
- 19 June 2020
What is CVE-2020-8162?
A security vulnerability exists in the ActiveStorage S3 adapter for Rails versions before 5.2.4.2 and 6.0.3.1, enabling attackers to manipulate the Content-Length of direct file uploads. This flaw allows end users to bypass specified upload size restrictions, potentially leading to unwanted server behavior or resource depletion.
Affected Version(s)
https://github.com/rails/rails rails >= 5.2.4.3, rails >= 6.0.3.1