NIXPKGS-2026-0742
GitHub issue
published 3 months ago
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
Rails Active Storage has possible content type bypass via metadata in direct uploads
-
https://github.com/rails/rails/security/advisories/GHSA-qcfx-2mfw-w4cg x_refsource_CONFIRM
-
https://github.com/rails/rails/releases/tag/v7.2.3.1 x_refsource_MISC
-
https://github.com/rails/rails/releases/tag/v8.0.4.1 x_refsource_MISC
-
https://github.com/rails/rails/releases/tag/v8.1.2.1 x_refsource_MISC
activestorage
- ==>= 8.1.0.beta1, < 8.1.2.1
- ==>= 8.0.0.beta1, < 8.0.4.1
- ==< 7.2.3.1