HIGH 8.8 RubyGems

Remote code execution via user-provided local names in ActionView

GHSA-cr3x-7m39-c6jq · BIT-rails-2020-8163 · CVE-2020-8163

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The is a code injection vulnerability in versions of Rails prior to 5.0.1 that would allow an attacker who controlled the locals argument of a render call to perform a RCE.

Ready to move

Start Securing

Free, no credit card | First findings in minutes