Paperclip
Thoughtbot · 2 CVEs
CVE-2017-0889
CRITICAL
paperclip: SSRF vulnerability in the Paperclip::UriAdapter class
Nov 13, 2017
CVE-2015-2963
MEDIUM
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validatio…
Jul 10, 2015
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2017-0889 | paperclip: SSRF vulnerability in the Paperclip::UriAdapter class | CRITICAL | 3.05% | Nov 13, 2017 |
| CVE-2015-2963 | The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to uplo… | MEDIUM | 2.12% | Jul 10, 2015 |
Showing 1 to 2 of 2 CVEs