paperclip Server-Side Request Forgery vulnerability
Critical severity
GitHub Reviewed
Published
Jan 22, 2018
to the GitHub Advisory Database
•
Updated Jan 26, 2023
Description
Published by the National Vulnerability Database
Nov 13, 2017
Published to the GitHub Advisory Database
Jan 22, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 26, 2023
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the
Paperclip::UriAdapter
class. Attackers may be able to access information about internal network resources.References