Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxhx-g4fq-49hj

Опубликовано: 29 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

CarrierWave Content-Type allowlist bypass vulnerability, possibly leading to XSS

Impact

CarrierWave::Uploader::ContentTypeAllowlist has a Content-Type allowlist bypass vulnerability, possibly leading to XSS.

The validation in allowlisted_content_type? determines Content-Type permissions by performing a partial match. If the content_type argument of allowlisted_content_type? is passed a value crafted by the attacker, Content-Types not included in the content_type_allowlist will be allowed.

In addition, by setting the Content-Type configured by the attacker at the time of file delivery, it is possible to cause XSS on the user's browser when the uploaded file is opened.

Patches

Upgrade to 3.0.5 or 2.2.5.

Workarounds

When validating with allowlisted_content_type? in CarrierWave::Uploader::ContentTypeAllowlist , forward match(\A) the Content-Type set in content_type_allowlist, preventing unintentional permission of text/html;image/png when you want to allow only image/png in content_type_allowlist.

References

OWASP - File Upload Cheat Sheet

Пакеты

Наименование

carrierwave

rubygems
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.5

3.0.5

Наименование

carrierwave

rubygems
Затронутые версииВерсия исправления

< 2.2.5

2.2.5

EPSS

Процентиль: 35%
0.00141
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 2 лет назад

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. The validation in `allowlisted_content_type?` determines Content-Type permissions by performing a partial match. If the `content_type` argument of `allowlisted_content_type?` is passed a value crafted by the attacker, Content-Types not included in the `content_type_allowlist` will be allowed. This issue has been patched in versions 2.2.5 and 3.0.5.

CVSS3: 6.8
nvd
около 2 лет назад

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. The validation in `allowlisted_content_type?` determines Content-Type permissions by performing a partial match. If the `content_type` argument of `allowlisted_content_type?` is passed a value crafted by the attacker, Content-Types not included in the `content_type_allowlist` will be allowed. This issue has been patched in versions 2.2.5 and 3.0.5.

CVSS3: 6.8
debian
около 2 лет назад

CarrierWave is a solution for file uploads for Rails, Sinatra and othe ...

EPSS

Процентиль: 35%
0.00141
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-79