CVE-2020-8151
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
02 / AFFECTED SOFTWARE
Affected packages
4 explicit affected versions
120 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
05 / REFERENCES
Further evidence
- https://groups.google.com/forum/#%21topic/rubyonrails-security/pktoF4VmiM8
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P7B7A4H22DZ522HLDS3JX3NX2CXIOZSR/
- https://github.com/rails/activeresource
- https://github.com/rails/activeresource/commit/0de18f7e96fa90bbf23b16ac11980bc2cb6a716e
- https://github.com/rails/rails/commit/0e969bdaf8ff2e3384350687aa0b583f94d6dfbc
- https://groups.google.com/forum/#!topic/rubyonrails-security/pktoF4VmiM8
- https://lists.fedoraproject.org/archives/list/[email protected]/message/P7B7A4H22DZ522HLDS3JX3NX2CXIOZSR
- https://nvd.nist.gov/vuln/detail/CVE-2020-8151