CRITICAL9.8
GHSA-5jcf-c5rg-rmm8
paperclip Server-Side Request Forgery vulnerability
Quick fix
GHSA-5jcf-c5rg-rmm8 — paperclip: upgrade to the fixed version with the command below.
bundle update paperclipDetails
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the `Paperclip::UriAdapter` class. Attackers may be able to access information about internal network resources.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-0889[ADVISORY]
- https://github.com/thoughtbot/paperclip/pull/2435[WEB]
- https://hackerone.com/reports/209430[WEB]
- https://hackerone.com/reports/713[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/paperclip/CVE-2017-0889.yml[WEB]
- https://github.com/thoughtbot/paperclip[PACKAGE]