CVE-2019-5420
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
- Affected products
- Alt Linux, Ruby On Rails, Suse
- Rubyonrails Rails
- < 5.2.2.1, 6.0.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 92.1% (100th percentile)
- Weakness
- CWE-77, CWE-330
- NVD status
- Modified
- Published
- 2019-03-27
CVE-2019-5420 at NVD
25 known exploits for CVE-2019-5420
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2019-5420
CVE-2019-5420
CVE-2019-5420
CVE-2019-5420
CVE-2019-5420
Rails-doubletap-RCE
CVE-2019-5420-PoC
cve-2019-5420
CVE-2019-5420.rb
ruby-RCE-CVE-2019-5420-
cve-2019-5420-POC
CVE-2019-5420
CVE-2019-5420-RCE
Exploit for Command Injection in Rubyonrails Rails
Exploit for Command Injection in Rubyonrails Rails
Exploit for Command Injection in Rubyonrails Rails
Exploit for Command Injection in Rubyonrails Rails
Exploit for Command Injection in Rubyonrails Rails
Ruby On Rails DoubleTap Development Mode secret_key_base Remote Code Execution Exploit
Ruby On Rails - DoubleTap Development Mode secret_key_base Remote Code Execution (Metasploit)
Ruby On Rails DoubleTap Development Mode secret_key_base Remote Code Execution
Immunity Canvas: RAILS_ACTIVESTORAGE_RCE
Exploit for Path Traversal in Rubyonrails Rails
Exploit for Command Injection in Rubyonrails Rails
Ruby On Rails DoubleTap Development Mode secret_key_base Vulnerability