A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
{ "versions": [ { "introduced": "0" }, { "fixed": "5.2.4.2" }, { "introduced": "6.0.0" }, { "fixed": "6.0.3.1" } ] }
[ { "events": [ { "introduced": "0" }, { "last_affected": "10.0" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-8162.json"