{"id":"GHSA-gxhx-g4fq-49hj","summary":"CarrierWave Content-Type allowlist bypass vulnerability, possibly leading to XSS","details":"### Impact\n[CarrierWave::Uploader::ContentTypeAllowlist](https://github.com/carrierwaveuploader/carrierwave/blob/master/lib/carrierwave/uploader/content_type_allowlist.rb) has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. \n\nThe validation in `allowlisted_content_type?` determines Content-Type permissions by performing a partial match.\nIf the `content_type` argument of `allowlisted_content_type?` is passed a value crafted by the attacker, Content-Types not included in the `content_type_allowlist` will be allowed.\n\nIn addition, by setting the Content-Type configured by the attacker at the time of file delivery, it is possible to cause XSS on the user's browser when the uploaded file is opened.\n\n### Patches\nUpgrade to [3.0.5](https://rubygems.org/gems/carrierwave/versions/3.0.5) or [2.2.5](https://rubygems.org/gems/carrierwave/versions/2.2.5).\n\n### Workarounds\nWhen validating with `allowlisted_content_type?` in [CarrierWave::Uploader::ContentTypeAllowlist](https://github.com/carrierwaveuploader/carrierwave/blob/master/lib/carrierwave/uploader/content_type_allowlist.rb) , forward match(`\\A`) the Content-Type set in `content_type_allowlist`, preventing unintentional permission of `text/html;image/png` when you want to allow only `image/png` in `content_type_allowlist`.\n\n### References\n[OWASP - File Upload Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/File_Upload_Cheat_Sheet.html#content-type-validation)\n","aliases":["CVE-2023-49090"],"modified":"2023-11-29T21:33:27Z","published":"2023-11-29T21:33:27Z","database_specific":{"github_reviewed_at":"2023-11-29T21:33:27Z","nvd_published_at":"2023-11-29T15:15:08Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/carrierwaveuploader/carrierwave/security/advisories/GHSA-gxhx-g4fq-49hj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49090"},{"type":"WEB","url":"https://github.com/carrierwaveuploader/carrierwave/commit/39b282db5c1303899b3d3381ce8a837840f983b5"},{"type":"WEB","url":"https://github.com/carrierwaveuploader/carrierwave/commit/863d425c76eba12c3294227b39018f6b2dccbbf3"},{"type":"PACKAGE","url":"https://github.com/carrierwaveuploader/carrierwave"},{"type":"WEB","url":"https://github.com/carrierwaveuploader/carrierwave/blob/master/lib/carrierwave/uploader/content_type_allowlist.rb"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/carrierwave/CVE-2023-49090.yml"},{"type":"WEB","url":"https://rubygems.org/gems/carrierwave/versions/2.2.5"},{"type":"WEB","url":"https://rubygems.org/gems/carrierwave/versions/3.0.5"}],"affected":[{"package":{"name":"carrierwave","ecosystem":"RubyGems","purl":"pkg:gem/carrierwave"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.5"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.0.3","3.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-gxhx-g4fq-49hj/GHSA-gxhx-g4fq-49hj.json"}},{"package":{"name":"carrierwave","ecosystem":"RubyGems","purl":"pkg:gem/carrierwave"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.5"}]}],"versions":["0.1","0.10.0","0.11.0","0.11.1","0.11.2","0.2.0","0.2.1","0.2.3","0.2.4","0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.3.5","0.3.5.1","0.3.5.2","0.4.0","0.4.1","0.4.10","0.4.2","0.4.3","0.4.4","0.4.5","0.4.6","0.4.7","0.4.8","0.4.9","0.5.0","0.5.0.beta2","0.5.1","0.5.2","0.5.3","0.5.4","0.5.5","0.5.6","0.5.7","0.5.8","0.6.0","0.6.1","0.6.2","0.7.0","0.7.1","0.8.0","0.9.0","1.0.0","1.0.0.beta","1.0.0.rc","1.1.0","1.2.0","1.2.1","1.2.2","1.2.3","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","2.0.0","2.0.0.rc","2.0.1","2.0.2","2.1.0","2.1.1","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-gxhx-g4fq-49hj/GHSA-gxhx-g4fq-49hj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N"}]}