paperclip
Easy upload management for ActiveRecord
Activity
- Latest release
- 8y ago
- Total releases
- 90
- Cadence
- ~23 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Apr 18, 2008
| Version | Released | |
|---|---|---|
6.1.0
minor
|
6.1.0
minor
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
6.0.0
major
|
6.0.0
major
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
5.3.0
minor
|
5.3.0
minor
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
5.2.1
patch
|
5.2.1
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
5.2.0
minor
|
5.2.0
minor
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
5.1.0
minor
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
5.1.0
minor
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
5.0.0
major
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
5.0.0
major
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
4.3.7
patch
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
4.3.7
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
5.0.0.beta2
pre
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
5.0.0.beta2
pre
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
5.0.0.beta1
pre
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
5.0.0.beta1
pre
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
4.3.6
patch
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
4.3.6
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
4.3.5
patch
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
4.3.5
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
4.3.4
patch
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
4.3.4
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
4.3.3
patch
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
4.3.3
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
4.3.2
patch
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
4.3.2
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
4.3.1
patch
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
4.3.1
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
4.2.4
patch
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
4.2.4
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
4.3.0
minor
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
4.3.0
minor
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
4.2.3
patch
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
4.2.3
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
4.2.2
patch
1 CVE
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev |
4.2.2
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
4.2.1
patch
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
4.2.1
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
4.2.0
minor
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
4.2.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
4.1.1
patch
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
4.1.1
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.1.0
minor
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
4.1.0
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.5.4
patch
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.5.4
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.0.0
major
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
4.0.0
major
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.5.3
patch
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.5.3
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.5.2
patch
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.5.2
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.5.1
patch
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.5.1
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.5.0
minor
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.5.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.4.2
patch
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.4.2
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.4.1
patch
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.4.1
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
2.7.5
patch
1 CVE
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev | ||
3.4.0
minor
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.4.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
2.7.4
patch
1 CVE
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev | ||
3.3.1
patch
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.3.1
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
2.7.2
patch
1 CVE
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev | ||
3.2.1
patch
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.2.1
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
2.8.0
minor
1 CVE
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev | ||
3.3.0
minor
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.3.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
2.7.1
patch
1 CVE
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev | ||
3.2.0
minor
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.2.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.1.4
patch
2 CVEs
CVE-2017-0889
GHSA-5jcf-c5rg-rmm8
Jan 22, 2018
paperclip Server-Side Request Forgery vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Affected versions
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
+ 21 more Show less
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
5.0.0
5.0.0.beta1
5.0.0.beta2
5.1.0
Fixed in
5.2.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.1.4
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.1.2
patch
1 CVE
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.1.2
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.1.1
patch
1 CVE
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.1.1
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.1.0
minor
1 CVE
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.1.0
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.0.4
patch
1 CVE
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.0.4
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.0.3
patch
1 CVE
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.0.3
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.0.2
major
1 CVE
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |
3.0.2
major
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
2.7.0
minor
1 CVE
CVE-2015-2963
GHSA-6jvm-3j5h-79f6
Oct 24, 2017
paperclip Cross-site Scripting vulnerability
Medium
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg. Affected versions
2.1.0
2.1.2
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
+ 58 more Show less
2.2.9.1
2.2.9.2
2.3.0
2.3.1
2.3.1.1
2.3.10
2.3.11
2.3.12
2.3.15
2.3.16
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.7.1
2.7.2
2.7.4
2.7.5
2.8.0
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
4.0.0
4.1.0
4.1.1
4.2.0
4.2.1
Fixed in
4.2.2
References
Updated Nov 30, 2024 · Source: OSV.dev |