A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.
https://hackerone.com/reports/899069
https://groups.google.com/g/rubyonrails-security/c/pAe9EV8gbM0