Ubuntu Security Update USN-7497-1: CarrierWave vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,812
Reaction score
74
Credits
-1,257
Rikita Ishikawa discovered that CarrierWave did not correctly sanitize certain inputs. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-21305) Norihide Saito discovered that CarrierWave did not correctly sanitize certain inputs. An attacker could possibly use this issue to execute a cross-site scripting (XSS) attack. (CVE-2023-49090)

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top