/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-29034

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-29034

Severity

6.8

Medium

CVSS V3

Summary

CarrierWave's Content-Type allowlist bypass vulnerability which possibly leads to XSS remained

Description

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-49090 wasn't fully addressed. This vulnerability is caused by the fact that when uploading to object storage, including Amazon S3, it is possible to set a Content-Type value that is interpreted by browsers to be different from what's allowed by content_type_allowlist, by providing multiple values separated by commas. This bypassed value can be used to cause XSS. Upgrade to 3.0.7 or 2.2.6.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing