VDB
Sign up
MEDIUM

GHSA-6jvm-3j5h-79f6

paperclip Cross-site Scripting vulnerability

Quick fix

GHSA-6jvm-3j5h-79f6 — paperclip: upgrade to the fixed version with the command below.

bundle update paperclip

Details

The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/paperclip
Introduced in: 0Fixed in: 4.2.2
Fixbundle update paperclip

References