icon

We found results for “

CVE-2023-49090

Good to know:

icon

Date: November 29, 2023

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. The validation in "allowlisted_content_type?" determines Content-Type permissions by performing a partial match. If the "content_type" argument of "allowlisted_content_type?" is passed a value crafted by the attacker, Content-Types not included in the "content_type_allowlist" will be allowed. This issue has been patched in versions 2.2.5 and 3.0.5.

Language: Ruby

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version carrierwave - 2.2.5;carrierwave - 3.0.5

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us