CVE-2023-49090General(carrierwave_project / carrierwave)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. The validation in `allowlisted_content_type?` determines Content-Type permissions by performing a partial match. If the `content_type` argument of `allowlisted_content_type?` is passed a value crafted by the attacker, Content-Types not included in the `content_type_allowlist` will be allowed. This issue has been patched in versions 2.2.5 and 3.0.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • carrierwave

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
carrierwave

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-23: 106-23
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
Full discourse1 post
  • nksistemas@nksistemas
    General

    CVE-2023-49090: La Vulnerabilidad de FFmpeg que Arma Archivos Multimedia https://nksistemas.com/cve-2023-49090-la-vulnerabilidad-de-ffmpeg-que-arma-archivos-multimedia/

    Post summary

    The content only includes the CVE identifier and a link to an article, with no further technical or exploit details.

    00001102
    6.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcarrierwave_projectcarrierwave-ruby-

Explore more