
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-8164 is a deserialization of untrusted data vulnerability discovered in Ruby on Rails versions < 5.2.4.3 and < 6.0.3.1. The vulnerability was reported through the HackerOne bug bounty program and was publicly disclosed on May 18, 2020 (Rails Security).
The vulnerability exists in ActionPack where user-supplied information can be inadvertently leaked from Strong Parameters. Specifically, the return values of each, each_value, or each_pair methods will return the underlying 'untrusted' hash of data read from the parameters. Applications that use these return values may inadvertently use untrusted user input. The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) (NVD Report).
When exploited, this vulnerability allows attackers to bypass Strong Parameters protection in Rails applications, potentially leading to unauthorized access to protected parameters. Applications that use the return values from the affected methods may unintentionally process untrusted user input (Rails Security).
The vulnerability can be exploited when applications use the return values of each, each_value, or each_pair methods in their parameter processing logic. For example, if an application uses these methods to process parameters and relies on their return values, an attacker could include malicious parameters that bypass the intended parameter restrictions (Rails Security).
The vulnerability has been fixed in Rails versions 5.2.4.3 and 6.0.3.1. As a workaround for users unable to upgrade immediately, it is recommended not to use the return values of each, each_value, or each_pair in applications. Patches were provided for the 5.2 and 6.0 series (Rails Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."