papercrop does not properly handle crop input
Published: May 24, 2022
SECURITY IDENTIFIERS
- CVE: CVE-2015-2784 (NVD)
- GHSA: GHSA-m44r-gv6q-9j9r
- Vendor Advisory: https://github.com/rsantamaria/papercrop/commit/b4ecd95debaf0a8712bd1d34def83f41fc6b3579
GEM
SEVERITY
CVSS v3.x: 9.8 (Critical)
PATCHED VERSIONS
>= 0.3.0
DESCRIPTION
The papercrop gem before 0.3.0 for Ruby on Rails does not properly handle crop input.
