Ruby on Rails Deserialization of Untrusted Data Vulnerability - CVE-2020-8165 - Vulnerability Database

Ruby on Rails Deserialization of Untrusted Data Vulnerability - CVE-2020-8165

Critical
Reference: CVE-2020-8165
Title: Ruby on Rails Deserialization of Untrusted Data Vulnerability
Overview:

A deserialization of untrusted data vulnernerability exists in rails lt 5.2.4.3 rails lt 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.