{"id":"CVE-2020-8159","aliases":["GHSA-mg5p-95m9-rmfp"],"url":"https://o3.security/vulnerability/CVE-2020-8159","summary":"Arbitrary file write in actionpack-page_caching gem","details":"There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.","published":"2020-05-12T13:15:13.250Z","modified":"2026-07-08T05:54:48.317078806Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"RubyGems","name":"actionpack-page_caching","fixedVersion":"1.2.1"}],"fix":null,"references":[{"type":"WEB","url":"https://groups.google.com/forum/#%21topic/rubyonrails-security/CFRVkEytdP8"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/07/msg00019.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:54:48.317078806Z"}}