Moderate severity vulnerability that affects paperclip
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Aug 13, 2018 
          to the GitHub Advisory Database
          •
          Updated Jan 9, 2023 
      
  
  
      Withdrawn
      This advisory was withdrawn on Jun 17, 2020
  
    
      Description
        Published to the GitHub Advisory Database
      Aug 13, 2018 
    
  
        Reviewed
      Jun 17, 2020 
    
  
        Withdrawn
      Jun 17, 2020 
    
  
        Last updated
      Jan 9, 2023 
    
  
Withdrawn, accidental duplicate publish.
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg.
References