Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21305

Опубликовано: 08 фев. 2021
Источник: nvd
CVSS3: 7.4
CVSS3: 8.8
CVSS2: 7.5
EPSS Низкий

Описание

CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipulate!" method inappropriately evals the content of mutation option(:read/:write), allowing attackers to craft a string that can be executed as a Ruby code. If an application developer supplies untrusted inputs to the option, it will lead to remote code execution(RCE). This is fixed in versions 1.3.2 and 2.1.1.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:carrierwave_project:carrierwave:*:*:*:*:*:ruby:*:*
Версия до 1.3.2 (исключая)
cpe:2.3:a:carrierwave_project:carrierwave:*:*:*:*:*:ruby:*:*
Версия от 2.0.1 (включая) до 2.1.1 (исключая)

EPSS

Процентиль: 86%
0.0282
Низкий

7.4 High

CVSS3

8.8 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-74
CWE-94

Связанные уязвимости

CVSS3: 7.4
ubuntu
почти 5 лет назад

CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipulate!" method inappropriately evals the content of mutation option(:read/:write), allowing attackers to craft a string that can be executed as a Ruby code. If an application developer supplies untrusted inputs to the option, it will lead to remote code execution(RCE). This is fixed in versions 1.3.2 and 2.1.1.

CVSS3: 7.4
debian
почти 5 лет назад

CarrierWave is an open-source RubyGem which provides a simple and flex ...

CVSS3: 7.4
github
почти 5 лет назад

Code Injection vulnerability in CarrierWave::RMagick

EPSS

Процентиль: 86%
0.0282
Низкий

7.4 High

CVSS3

8.8 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-74
CWE-94