Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33173

Опубликовано: 23 мар. 2026
Источник: redhat
CVSS3: 7.6

Описание

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, DirectUploadsController accepts arbitrary metadata from the client and persists it on the blob. Because internal flags like identified and analyzed are stored in the same metadata hash, a direct-upload client can set these flags to skip MIME detection and analysis. This allows an attacker to upload arbitrary content while claiming a safe content_type, bypassing any validations that rely on Active Storage's automatic content type identification. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

A flaw was found in Rails Active Storage. A remote attacker, acting as a direct-upload client, can exploit this vulnerability by manipulating metadata during file uploads. By setting internal flags, the attacker can bypass the system's automatic MIME (Multipurpose Internet Mail Extensions) type detection and analysis. This allows the attacker to upload arbitrary content, potentially circumventing security validations that rely on correct content type identification.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp20/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp21/systemAffected
Red Hat 3scale API Management Platform 23scale-amp21/zyncWill not fix
Red Hat 3scale API Management Platform 23scale-amp22/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp22/zyncWill not fix
Red Hat 3scale API Management Platform 23scale-amp24/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp24/zyncWill not fix
Red Hat 3scale API Management Platform 23scale-amp25/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp25/zyncAffected
Red Hat 3scale API Management Platform 23scale-amp26/systemAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1287
https://bugzilla.redhat.com/show_bug.cgi?id=2450545Rails: Active Storage: Rails Active Storage: Content type bypass via arbitrary metadata in direct uploads

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary metadata from the client and persists it on the blob. Because internal flags like `identified` and `analyzed` are stored in the same metadata hash, a direct-upload client can set these flags to skip MIME detection and analysis. This allows an attacker to upload arbitrary content while claiming a safe `content_type`, bypassing any validations that rely on Active Storage's automatic content type identification. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 5.3
nvd
4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary metadata from the client and persists it on the blob. Because internal flags like `identified` and `analyzed` are stored in the same metadata hash, a direct-upload client can set these flags to skip MIME detection and analysis. This allows an attacker to upload arbitrary content while claiming a safe `content_type`, bypassing any validations that rely on Active Storage's automatic content type identification. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 5.3
debian
4 месяца назад

Active Storage allows users to attach cloud and local files in Rails a ...

github
4 месяца назад

Rails Active Storage has possible content type bypass via metadata in direct uploads

CVSS3: 5.3
fstec
4 месяца назад

Уязвимость компонента Active Storage программной платформы Ruby on Rails, позволяющая нарушителю выполнить произвольный код

7.6 High

CVSS3