Логотип exploitDog
bind:CVE-2023-49090
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-49090

Количество 4

Количество 4

ubuntu логотип

CVE-2023-49090

около 2 лет назад

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. The validation in `allowlisted_content_type?` determines Content-Type permissions by performing a partial match. If the `content_type` argument of `allowlisted_content_type?` is passed a value crafted by the attacker, Content-Types not included in the `content_type_allowlist` will be allowed. This issue has been patched in versions 2.2.5 and 3.0.5.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2023-49090

около 2 лет назад

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. The validation in `allowlisted_content_type?` determines Content-Type permissions by performing a partial match. If the `content_type` argument of `allowlisted_content_type?` is passed a value crafted by the attacker, Content-Types not included in the `content_type_allowlist` will be allowed. This issue has been patched in versions 2.2.5 and 3.0.5.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2023-49090

около 2 лет назад

CarrierWave is a solution for file uploads for Rails, Sinatra and othe ...

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-gxhx-g4fq-49hj

около 2 лет назад

CarrierWave Content-Type allowlist bypass vulnerability, possibly leading to XSS

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-49090

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. The validation in `allowlisted_content_type?` determines Content-Type permissions by performing a partial match. If the `content_type` argument of `allowlisted_content_type?` is passed a value crafted by the attacker, Content-Types not included in the `content_type_allowlist` will be allowed. This issue has been patched in versions 2.2.5 and 3.0.5.

CVSS3: 6.8
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-49090

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. The validation in `allowlisted_content_type?` determines Content-Type permissions by performing a partial match. If the `content_type` argument of `allowlisted_content_type?` is passed a value crafted by the attacker, Content-Types not included in the `content_type_allowlist` will be allowed. This issue has been patched in versions 2.2.5 and 3.0.5.

CVSS3: 6.8
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-49090

CarrierWave is a solution for file uploads for Rails, Sinatra and othe ...

CVSS3: 6.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-gxhx-g4fq-49hj

CarrierWave Content-Type allowlist bypass vulnerability, possibly leading to XSS

CVSS3: 6.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу