
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was discovered in the actionpack_page-caching Ruby gem (CVE-2020-8159), affecting versions prior to v1.2.1. This security issue was identified in the static page caching module for Rails. The vulnerability was disclosed on May 12, 2020, and affects web servers using the vulnerable versions of the gem (NVD, Debian Security).
The vulnerability allows attackers to write arbitrary files to a web server. The issue is particularly severe when an attacker can write unescaped ERB (Embedded Ruby) to a view, which could potentially lead to remote code execution (Debian LTS).
The primary impact of this vulnerability is the potential for remote code execution on affected web servers. The ability to write arbitrary files to the web server could allow attackers to compromise the system's integrity and potentially execute malicious code (NVD).
The vulnerability requires an attacker to have the ability to write unescaped ERB to a view in order to achieve remote code execution. The specific conditions for exploitation involve the ability to interact with the page caching functionality of the affected Rails applications (Debian Security).
The vulnerability has been fixed in version 1.2.1 and later releases of the actionpack_page-caching gem. For Debian 9 (stretch) users, the fix was implemented in version 1.0.2-4+deb9u1. It is recommended to upgrade the ruby-actionpack-page-caching packages to the patched versions (Debian LTS).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."