4.3
CVSSv3

CVE-2021-21288

Published: 08/02/2021 Updated: 12/02/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave prior to 1.3.2 and 2.1.1 the download feature has an SSRF vulnerability, allowing attacks to provide DNS entries or IP addresses that are intended for internal use and gather information about the Intranet infrastructure of the platform. This is fixed in versions 1.3.2 and 2.1.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

carrierwave project carrierwave

Vendor Advisories

Debian Bug report logs - #982552 ruby-carrierwave: CVE-2021-21288 Package: src:ruby-carrierwave; Maintainer for src:ruby-carrierwave is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 11 Feb 2021 17:45:01 UTC Severi ...