CVE-2019-5420
CRITICAL 9.8EPSS 92.1%
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.0
- 9.8 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 92.14% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2019-03-27
- Updated
- 2024-08-04
Proof-of-concept exploits (14)
- http://packetstormsecurity.com/files/152704/Ruby-On-Rails-DoubleTap-Development-Mode-secr…
- AnasTaoutaou/CVE-2019-54200★ · 2021-01-11
- Eremiel/CVE-2019-54200★ · 2021-01-20
- PenTestical/CVE-2019-54200★ · 2022-06-06
- WildWestCyberSecurity/cve-2019-5420-POC1★ · 2026-07-13
- cved-sources/cve-2019-54200★ · 2023-01-19
- j4k0m/CVE-2019-54205★ · 2021-09-07
- knqyf263/CVE-2019-54208★ · 2019-03-21
- laffray/ruby-RCE-CVE-2019-5420-5★ · 2022-07-02
- mmeza-developer/CVE-2019-5420-RCE0★ · 2021-11-06
- mpgn/Rails-doubletap-RCE132★ · 2023-01-19
- scumdestroy/CVE-2019-5420.rb3★ · 2022-01-12
- sealldeveloper/CVE-2019-5420-PoC0★ · 2026-02-11
- trickstersec/CVE-2019-54200★ · 2022-03-14