PT-2015-6011 · Ruby · Paperclip

Mori Shingo

·

Published

2015-07-10

·

Updated

2018-08-13

·

CVE-2015-2963

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions paperclip gem versions prior to 4.2.2
Description The issue allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed content-type value. This can be achieved by providing a false content-type value, such as image/jpeg, to bypass media-type validation and upload malicious files.
Recommendations For versions prior to 4.2.2, update to version 4.2.2 or later to resolve the issue. As a temporary workaround, consider implementing additional validation for the content-type value to prevent spoofing attacks. Restrict access to upload functionality to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2963
GHSA-6JVM-3J5H-79F6
GHSA-PHMW-PV3F-VVX7

Affected Products

Paperclip