Back to search
CVE-2017-0889
Published: Nov 13, 2017
Modified: Sep 16, 2024
PUBLISHED
Description
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about internal network resources.
| Vendor | Product | Versions |
|---|---|---|
thoughtbot | paperclip ruby gem | affected All versions since 3.1.4 |
Weaknesses (CWE)
References
https://hackerone.com/reports/209430
x_refsource_MISC
https://github.com/thoughtbot/paperclip/pull/2435
x_refsource_CONFIRM
https://hackerone.com/reports/713
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now