{"schema_version":"1.7.3","id":"GHSA-m42x-37p3-fv5w","published":"2020-05-26T15:09:48Z","modified":"2024-02-22T05:37:26.373913Z","aliases":["CVE-2020-8162"],"summary":"Circumvention of file size limits in ActiveStorage","details":"There is a vulnerability in ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user.\n\nVersions Affected:  rails < 5.2.4.2, rails < 6.0.3.1\nNot affected:       Applications that do not use the direct upload functionality of the ActiveStorage S3 adapter.\nFixed Versions:     rails >= 5.2.4.3, rails >= 6.0.3.1\n\nImpact\n------\n\nUtilizing this vulnerability, an attacker can control the Content-Length of an S3 direct upload URL without receiving a new signature from the server. This could be used to bypass controls in place on the server to limit upload size.\n\nWorkarounds\n-----------\n\nThis is a low-severity security issue. As such, no workaround is necessarily until such time as the application can be upgraded.","affected":[{"package":{"name":"activestorage","ecosystem":"RubyGems","purl":"pkg:gem/activestorage"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.2.4.3"}]}],"versions":["5.2.0","5.2.0.beta1","5.2.0.beta2","5.2.0.rc1","5.2.0.rc2","5.2.1","5.2.1.1","5.2.1.rc1","5.2.2","5.2.2.1","5.2.2.rc1","5.2.3","5.2.3.rc1","5.2.4","5.2.4.1","5.2.4.2","5.2.4.rc1"],"database_specific":{"last_known_affected_version_range":"<= 5.2.4.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-m42x-37p3-fv5w/GHSA-m42x-37p3-fv5w.json"}},{"package":{"name":"activestorage","ecosystem":"RubyGems","purl":"pkg:gem/activestorage"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.0.3.1"}]}],"versions":["6.0.0","6.0.1","6.0.1.rc1","6.0.2","6.0.2.1","6.0.2.2","6.0.2.rc1","6.0.2.rc2","6.0.3","6.0.3.rc1"],"database_specific":{"last_known_affected_version_range":"<= 6.0.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-m42x-37p3-fv5w/GHSA-m42x-37p3-fv5w.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-8162"},{"type":"WEB","url":"https://github.com/aws/aws-sdk-ruby/issues/2098"},{"type":"WEB","url":"https://hackerone.com/reports/789579"},{"type":"WEB","url":"https://github.com/aws/aws-sdk-ruby"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2020-8162.yml"},{"type":"WEB","url":"https://groups.google.com/forum/#!topic/rubyonrails-security/PjU3946mreQ"},{"type":"WEB","url":"https://groups.google.com/g/rubyonrails-security/c/PjU3946mreQ"},{"type":"WEB","url":"https://www.debian.org/security/2020/dsa-4766"}],"database_specific":{"cwe_ids":["CWE-434","CWE-602"],"github_reviewed":true,"github_reviewed_at":"2020-05-26T15:06:42Z","nvd_published_at":"2020-06-19T17:15:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}