CVE-2017-0889

critical
Published 2018-01-23 · Modified 2023-11-08
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

paperclip Server-Side Request Forgery vulnerability

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: support@hackerone.com — https://github.com/thoughtbot/paperclip/pull/2435

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemspaperclip<>= 5.2.0>= 5.2.0
ruby RubyGemspaperclip>=3.1.4,<5.2.05.2.0

Application impact

VendorProductVersionsFixed
thoughtbotpaperclip{"startIncluding":"3.1.4","endExcluding":"5.2.0"}5.2.0

References

CWEs

CWE-918

Verify integrity in audit chain (admin only). AS-IS.