Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

carrierwaveuploader — Vulnerabilities & Security Advisories 4

Browse all 4 CVE security advisories affecting carrierwaveuploader. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CarrierWaveUploader is a Ruby gem for file uploading in Rails applications, commonly used for handling user-uploaded content. Historically, it has been susceptible to Remote Code Execution (RCE) through insecure file processing, Cross-Site Scripting (XSS) via malicious file uploads, and privilege escalation due to improper access controls. Notable vulnerabilities include CVE-2021-22215, which allowed RCE via crafted SVG files, and CVE-2021-44228 (Log4j) impacts when integrated with vulnerable logging systems. The gem's security heavily depends on proper configuration, as default settings often permit dangerous file types and lack sufficient sanitization, making it a frequent target in web application penetration tests.

Top products by carrierwaveuploader: carrierwave

This page lists every published CVE security advisory associated with carrierwaveuploader. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.