{"id":"CVE-2020-8185","aliases":["GHSA-c6qr-h5vq-59jc"],"url":"https://o3.security/vulnerability/CVE-2020-8185","summary":"Untrusted users can run pending migrations in production in Rails","details":"A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.","published":"2020-07-02T19:15:12.747Z","modified":"2026-08-07T11:31:28.138462452Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"RubyGems","name":"actionpack","fixedVersion":"6.0.3.2"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XJ7NUWXAEVRQCROIIBV4C6WXO6IR3KSB/"},{"type":"REPORT","url":"https://hackerone.com/reports/899069"},{"type":"FIX","url":"https://groups.google.com/g/rubyonrails-security/c/pAe9EV8gbM0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:28.138462452Z"}}