CVE-2024-29034

MEDIUM
Published Mar 24, 2024 Modified Nov 7, 2025 CWE-79 CWE-436

Description

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-49090 wasn't fully addressed. This vulnerability is caused by the fact that when uploading to object storage, including Amazon S3, it is possible to set a Content-Type value that is interpreted by browsers to be different from what's allowed by `content_type_allowlist`, by providing multiple values separated by commas. This bypassed value can be used to cause XSS. Upgrade to 3.0.7 or 2.2.6.

Is your site exposed to CVE-2024-29034?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.8
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

Weakness Type (CWE)

CWE-79 Cross-site Scripting (XSS)
CWE-436 CWE-436

Affected Products

Vendor Product
carrierwave_project carrierwave
carrierwave_project carrierwave

References

Frequently Asked Questions

What is CVE-2024-29034? +
CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-49090 wasn't fully addressed. This vulnerability is caused by the fact that when uploading to object storage, including Amazon S3, it is possible to set a Content-Type value that is interpreted by browsers to be different from what's allowed by `content_type_allowlist`, by providing multiple values separated by commas. This bypassed value can be used to cause XSS. Upgrade to 3.0.7 or 2.2.6. It has a CVSS v3.1 base score of 6.8 (MEDIUM).
How severe is CVE-2024-29034? +
CVE-2024-29034 has a CVSS v3.1 score of 6.8 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-29034? +
CVE-2024-29034 affects products from carrierwave_project, specifically: carrierwave. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-29034? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-29034 — free, no signup required.