CVE-2020-8164
Ruby vulnerability analysis and mitigation

Overview

CVE-2020-8164 is a deserialization of untrusted data vulnerability discovered in Ruby on Rails versions < 5.2.4.3 and < 6.0.3.1. The vulnerability was reported through the HackerOne bug bounty program and was publicly disclosed on May 18, 2020 (Rails Security).

Technical details

The vulnerability exists in ActionPack where user-supplied information can be inadvertently leaked from Strong Parameters. Specifically, the return values of each, each_value, or each_pair methods will return the underlying 'untrusted' hash of data read from the parameters. Applications that use these return values may inadvertently use untrusted user input. The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) (NVD Report).

Impact

When exploited, this vulnerability allows attackers to bypass Strong Parameters protection in Rails applications, potentially leading to unauthorized access to protected parameters. Applications that use the return values from the affected methods may unintentionally process untrusted user input (Rails Security).

Exploitability

The vulnerability can be exploited when applications use the return values of each, each_value, or each_pair methods in their parameter processing logic. For example, if an application uses these methods to process parameters and relies on their return values, an attacker could include malicious parameters that bypass the intended parameter restrictions (Rails Security).

Mitigation and workarounds

The vulnerability has been fixed in Rails versions 5.2.4.3 and 6.0.3.1. As a workaround for users unable to upgrade immediately, it is recommended not to use the return values of each, each_value, or each_pair in applications. Patches were provided for the 5.2 and 6.0 series (Rails Security).

Additional resources


SourceThis report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NoYesAug 18, 2026
CVE-2026-61666HIGH8.9
  • Ruby logoRuby
  • websocket-driver
NoYesAug 17, 2026
CVE-2026-73648MEDIUM5.1
  • Ruby logoRuby
  • ruby3.4-rails-8.1
NoYesAug 13, 2026
CVE-2026-73426MEDIUM4.6
  • JavaScript logoJavaScript
  • action_text-trix
NoYesAug 18, 2026
CVE-2026-73428MEDIUM4.6
  • JavaScript logoJavaScript
  • action_text-trix
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management