Description
A vulnerability exists in versions of Rails prior to 5.0.1 that would allow an attacker who controlled the locals argument of a render call to acheive remote code execution. This vulnerability has been assigned the CVE identifier CVE-2020-8163.
Remediation
Users of Rails 5.0 should upgrade to a version >= 5.0.1. This release is already
available on RubyGems.
Workaround: Until such time as the patch can be applied, application developers should
ensure that all user-provided local names are alphanumeric.
References
Related Vulnerabilities
Ektron CMS multiple vulnerabilities
Drupal Core 8.4.x Remote Code Execution (8.4.0 - 8.4.7)
Microsoft Exchange Server Pre-auth Path Confusion vulnerability (CVE-2021-34473)
Oracle Access Manager 'opensso' Deserialization RCE (CVE-2021-35587)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-46243)