CVE-2024-29034
CVSS V2 None
CVSS V3 None
Description
CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-49090 wasn't fully addressed. This vulnerability is caused by the fact that when uploading to object storage, including Amazon S3, it is possible to set a Content-Type value that is interpreted by browsers to be different from what's allowed by `content_type_allowlist`, by providing multiple values separated by commas. This bypassed value can be used to cause XSS. Upgrade to 3.0.7 or 2.2.6.
Overview
- CVE ID
- CVE-2024-29034
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-03-24T19:27:35.996Z
- Last Modified Date
- 2024-03-24T20:05:20.176Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/carrierwaveuploader/carrierwave/security/advisories/GHSA-vfmv-jfc5-pjjw | x_refsource_CONFIRM |
https://github.com/carrierwaveuploader/carrierwave/commit/25b1c800d45ef8e78dc445ebe3bd8a6e3f0a3477 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-29034 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-29034 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 02:55:21 | Added to TrackCVE |