{"id":1765,"date":"2021-01-29T20:57:31","date_gmt":"2021-01-30T01:57:31","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=1765"},"modified":"2021-01-29T20:57:33","modified_gmt":"2021-01-30T01:57:33","slug":"ruby-on-rails-vulnerabilities-of-this-program","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/","title":{"rendered":"Ruby on Rails &#8211; Vulnerabilities of this program"},"content":{"rendered":"\n<p>Taking into account that the Ruby on Rails website itself defines it as &#8220;a framework for building web applications that access databases&#8221;, you can get a clear idea of \u200b\u200bwhat Ruby on Rails is for.<\/p>\n\n\n\n<p>Ruby on Rails is free software that can be downloaded and installed for free. There are many uses of Ruby on Rails in a company, we just have to see what it has been used for previously, for example: Twitter, Hulu, etc, and this based on multinationals.<\/p>\n\n\n\n<p>Although it seems very good and everything is fine, this unfortunately as in all applications has had and may have vulnerabilities for which you have to be very careful and we will analyze some of these that were found a while ago.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Vulnerabilities found in Ruby on Rails<\/h2>\n\n\n\n<p><strong><em>\u25b8CVE-2020-8264<\/em><\/strong><\/p>\n\n\n\n<p>With this vulnerability it is possible that when an application runs in development mode and allows an attacker to send or embed (on another page) a specially crafted URL that can allow the attacker to execute JavaScript in the context of the local application counting on a qualification of 6.1 in terms of riskand this was also discovered recently.<\/p>\n\n\n\n<p><strong><em>\u25b8CVE-2020-8163<\/em><\/strong><\/p>\n\n\n\n<p>This vulnerability can be exploited with network access and requires a small amount of user privileges with a score of 8.8 this is a code injection vulnerability in Rails versions prior to 5.0.1 that would allow an attacker which controlled the locals argument of a render call to perform an RCE.<\/p>\n\n\n\n<p><strong><em>\u25b8CVE-2020-8165<\/em><\/strong><\/p>\n\n\n\n<p>These vulnerabilities can be exploited with network access and do not require authorization privileges or user interaction. This vulnerability is considered to have low attack complexity. It has the highest possible exploitability rating of 3.9 and the potential impact of an exploitation of this vulnerability is considered critical since this vulnerability has a high impact on confidentiality, integrity with a rating of 9.8.<br><br>See also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/issues-and-vulnerabilities-faced-by-python\/\">Issues and vulnerabilities faced by Python<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/perl-what-you-should-know-about-it\/\">PERL \u2013 What you should know about it<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Taking into account that the Ruby on Rails website itself defines it as &#8220;a framework for building web applications that access databases&#8221;, you can get a clear idea of \u200b\u200bwhat Ruby on Rails is for. Ruby on Rails is free software that can be downloaded and installed for free. There are many uses of Ruby [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1766,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36,197],"class_list":["post-1765","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-vulnerabilities"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Ruby on Rails - Vulnerabilities of this program - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Ruby on Rails also known as an application building software we will analyze some vulnerabilities of this and thus be able to be prevented...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ruby on Rails - Vulnerabilities of this program - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Ruby on Rails also known as an application building software we will analyze some vulnerabilities of this and thus be able to be prevented...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-01-30T01:57:31+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-01-30T01:57:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/Ruby.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Ruby on Rails &#8211; Vulnerabilities of this program\",\"datePublished\":\"2021-01-30T01:57:31+00:00\",\"dateModified\":\"2021-01-30T01:57:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/\"},\"wordCount\":327,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/Ruby.png\",\"keywords\":[\"Cybersecurity\",\"Vulnerabilities\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/\",\"name\":\"Ruby on Rails - Vulnerabilities of this program - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/Ruby.png\",\"datePublished\":\"2021-01-30T01:57:31+00:00\",\"dateModified\":\"2021-01-30T01:57:33+00:00\",\"description\":\"Ruby on Rails also known as an application building software we will analyze some vulnerabilities of this and thus be able to be prevented...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/Ruby.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/01\\\/Ruby.png\",\"width\":1200,\"height\":720},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ruby-on-rails-vulnerabilities-of-this-program\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Ruby on Rails &#8211; Vulnerabilities of this program\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Ruby on Rails - Vulnerabilities of this program - Truxgo Server Blog","description":"Ruby on Rails also known as an application building software we will analyze some vulnerabilities of this and thus be able to be prevented...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/","og_locale":"es_MX","og_type":"article","og_title":"Ruby on Rails - Vulnerabilities of this program - Truxgo Server Blog","og_description":"Ruby on Rails also known as an application building software we will analyze some vulnerabilities of this and thus be able to be prevented...","og_url":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-01-30T01:57:31+00:00","article_modified_time":"2021-01-30T01:57:33+00:00","og_image":[{"width":1200,"height":720,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/Ruby.png","type":"image\/png"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Ruby on Rails &#8211; Vulnerabilities of this program","datePublished":"2021-01-30T01:57:31+00:00","dateModified":"2021-01-30T01:57:33+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/"},"wordCount":327,"commentCount":2,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/Ruby.png","keywords":["Cybersecurity","Vulnerabilities"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/","url":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/","name":"Ruby on Rails - Vulnerabilities of this program - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/Ruby.png","datePublished":"2021-01-30T01:57:31+00:00","dateModified":"2021-01-30T01:57:33+00:00","description":"Ruby on Rails also known as an application building software we will analyze some vulnerabilities of this and thus be able to be prevented...","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/Ruby.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/01\/Ruby.png","width":1200,"height":720},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/ruby-on-rails-vulnerabilities-of-this-program\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Ruby on Rails &#8211; Vulnerabilities of this program"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1765","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=1765"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1765\/revisions"}],"predecessor-version":[{"id":1778,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1765\/revisions\/1778"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/1766"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=1765"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=1765"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=1765"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}