Описание
paperclip Server-Side Request Forgery vulnerability
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources.
Пакеты
Наименование
paperclip
rubygems
Затронутые версииВерсия исправления
>= 3.1.4, < 5.2.0
5.2.0
Связанные уязвимости
CVSS3: 4.3
redhat
почти 9 лет назад
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources.
CVSS3: 9.8
nvd
около 8 лет назад
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources.