Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fwcm-636p-68r5

Опубликовано: 08 фев. 2021
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Server-side request forgery in CarrierWave

Impact

CarrierWave download feature has an SSRF vulnerability, allowing attacks to provide DNS entries or IP addresses that are intended for internal use and gather information about the Intranet infrastructure of the platform.

Patches

Upgrade to 2.1.1 or 1.3.2.

Workarounds

Using proper network segmentation and applying the principle of least privilege to outbound connections from application servers can reduce the severity of SSRF vulnerabilities. Ideally the vulnerable gem should run on an isolated server without access to any internal network resources or cloud metadata access.

References

Server-Side Request Forgery Prevention Cheat Sheet

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

carrierwave

rubygems
Затронутые версииВерсия исправления

< 1.3.2

1.3.2

Наименование

carrierwave

rubygems
Затронутые версииВерсия исправления

>= 2.0.0, < 2.1.1

2.1.1

EPSS

Процентиль: 42%
0.002
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 5 лет назад

CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1 the download feature has an SSRF vulnerability, allowing attacks to provide DNS entries or IP addresses that are intended for internal use and gather information about the Intranet infrastructure of the platform. This is fixed in versions 1.3.2 and 2.1.1.

CVSS3: 4.3
nvd
почти 5 лет назад

CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1 the download feature has an SSRF vulnerability, allowing attacks to provide DNS entries or IP addresses that are intended for internal use and gather information about the Intranet infrastructure of the platform. This is fixed in versions 1.3.2 and 2.1.1.

CVSS3: 4.3
debian
почти 5 лет назад

CarrierWave is an open-source RubyGem which provides a simple and flex ...

EPSS

Процентиль: 42%
0.002
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-918