CVE-2020-8165: Deserialization of Untrusted Data
(updated )
A deserialization of untrusted data vulnernerability exists in rails that can allow an attacker to unmarshal user-provided objects in MemCacheStore
and RedisCacheStore
potentially resulting in an RCE.
References
Detect and mitigate CVE-2020-8165 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →