{"id":"GHSA-5jcf-c5rg-rmm8","summary":"paperclip Server-Side Request Forgery vulnerability","details":"Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the `Paperclip::UriAdapter` class. Attackers may be able to access information about internal network resources.","aliases":["CVE-2017-0889"],"modified":"2023-11-08T03:58:40.490849Z","published":"2018-01-22T13:31:34Z","database_specific":{"github_reviewed_at":"2020-06-16T21:16:31Z","nvd_published_at":"2017-11-13T17:29:00Z","cwe_ids":["CWE-918"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-0889"},{"type":"WEB","url":"https://github.com/thoughtbot/paperclip/pull/2435"},{"type":"WEB","url":"https://hackerone.com/reports/209430"},{"type":"WEB","url":"https://hackerone.com/reports/713"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/paperclip/CVE-2017-0889.yml"},{"type":"PACKAGE","url":"https://github.com/thoughtbot/paperclip"}],"affected":[{"package":{"name":"paperclip","ecosystem":"RubyGems","purl":"pkg:gem/paperclip"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1.4"},{"fixed":"5.2.0"}]}],"versions":["3.1.4","3.2.0","3.2.1","3.3.0","3.3.1","3.4.0","3.4.1","3.4.2","3.5.0","3.5.1","3.5.2","3.5.3","3.5.4","4.0.0","4.1.0","4.1.1","4.2.0","4.2.1","4.2.2","4.2.3","4.2.4","4.3.0","4.3.1","4.3.2","4.3.3","4.3.4","4.3.5","4.3.6","4.3.7","5.0.0","5.0.0.beta1","5.0.0.beta2","5.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/01/GHSA-5jcf-c5rg-rmm8/GHSA-5jcf-c5rg-rmm8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}