CVE-2024-29034 - CVE House
Back to Database
Status published Medium CVE-2024-29034

CarrierWave's Content-Type allowlist bypass vulnerability which possibly leads to XSS remained

Vulnerability Description

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-49090 wasn't fully addressed. This vulnerability is caused by the fact that when uploading to object storage, including Amazon S3, it is possible to set a Content-Type value that is interpreted by browsers to be different from what's allowed by `content_type_allowlist`, by providing multiple values separated by commas. This bypassed value can be used to cause XSS. Upgrade to 3.0.7 or 2.2.6.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-29034

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

carrierwaveuploader

View all reports →

Affected Software

carrierwave
Vulnerable Versions:
>= 3.0.0, < 3.0.7, < 2.2.6

Timeline

Official Publish: March 24th, 2024
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

Weaknesses (CWE)