Описание
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, DirectUploadsController accepts arbitrary metadata from the client and persists it on the blob. Because internal flags like identified and analyzed are stored in the same metadata hash, a direct-upload client can set these flags to skip MIME detection and analysis. This allows an attacker to upload arbitrary content while claiming a safe content_type, bypassing any validations that rely on Active Storage's automatic content type identification. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
A flaw was found in Rails Active Storage. A remote attacker, acting as a direct-upload client, can exploit this vulnerability by manipulating metadata during file uploads. By setting internal flags, the attacker can bypass the system's automatic MIME (Multipurpose Internet Mail Extensions) type detection and analysis. This allows the attacker to upload arbitrary content, potentially circumventing security validations that rely on correct content type identification.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat 3scale API Management Platform 2 | 3scale-amp20/system | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp21/system | Affected | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp21/zync | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp22/system | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp22/zync | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp24/system | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp24/zync | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp25/system | Will not fix | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp25/zync | Affected | ||
| Red Hat 3scale API Management Platform 2 | 3scale-amp26/system | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
7.6 High
CVSS3
Связанные уязвимости
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary metadata from the client and persists it on the blob. Because internal flags like `identified` and `analyzed` are stored in the same metadata hash, a direct-upload client can set these flags to skip MIME detection and analysis. This allows an attacker to upload arbitrary content while claiming a safe `content_type`, bypassing any validations that rely on Active Storage's automatic content type identification. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary metadata from the client and persists it on the blob. Because internal flags like `identified` and `analyzed` are stored in the same metadata hash, a direct-upload client can set these flags to skip MIME detection and analysis. This allows an attacker to upload arbitrary content while claiming a safe `content_type`, bypassing any validations that rely on Active Storage's automatic content type identification. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Active Storage allows users to attach cloud and local files in Rails a ...
Rails Active Storage has possible content type bypass via metadata in direct uploads
Уязвимость компонента Active Storage программной платформы Ruby on Rails, позволяющая нарушителю выполнить произвольный код
7.6 High
CVSS3