VDB
Sign up
MEDIUM

GHSA-qcfx-2mfw-w4cg

Rails Active Storage has possible content type bypass via metadata in direct uploads

Quick fix

GHSA-qcfx-2mfw-w4cg — activestorage: upgrade to the fixed version with the command below.

bundle update activestorage

Details

### Impact Active Storage's `DirectUploadsController` accepts arbitrary metadata from the client and persists it on the blob. Because internal flags like `identified` and `analyzed` are stored in the same metadata hash, a malicious direct-upload client could set these flags.

### Releases The fixed releases are available at the normal locations.

### Credit This was responsible reported by Hackerone researcher [pwnie](https://hackerone.com/pwnie)

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activestorage
Introduced in: 8.1.0.beta1Fixed in: 8.1.2.1
Fixbundle update activestorage
RubyGems/activestorage
Introduced in: 8.0.0.beta1Fixed in: 8.0.4.1
Fixbundle update activestorage
RubyGems/activestorage
Introduced in: 0Fixed in: 7.2.3.1
Fixbundle update activestorage

References