Debian Package Tracker
Register | Log in
Subscribe

ruby-carrierwave

Ruby file upload library

Choose email to subscribe with

general
  • source: ruby-carrierwave (main)
  • version: 1.3.2-2
  • maintainer: Debian Ruby Extras Maintainers (archive) (DMD)
  • uploaders: Pirate Praveen [DMD]
  • arch: all
  • std-ver: 4.5.1
  • VCS: Git (Browse)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.3.1-2
  • stable: 1.3.2-2
versioned links
  • 1.3.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.3.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ruby-carrierwave
package is gone
This package is not in any development repository. This probably means that the package has been removed (or has been renamed). Thus the information here is of little interest ... the package is going to disappear unless someone takes it over and reintroduces it.
action needed
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2023-49090: (needs triaging) CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. The validation in `allowlisted_content_type?` determines Content-Type permissions by performing a partial match. If the `content_type` argument of `allowlisted_content_type?` is passed a value crafted by the attacker, Content-Types not included in the `content_type_allowlist` will be allowed. This issue has been patched in versions 2.2.5 and 3.0.5.

You can find information about how to handle this issue in the security team's documentation.

Created: 2024-03-25 Last update: 2025-04-23 07:02
news
[rss feed]
  • [2025-04-22] Removed 3.0.7-1 from unstable (Debian FTP Masters)
  • [2025-03-11] ruby-carrierwave REMOVED from testing (Debian testing watch)
  • [2024-07-30] ruby-carrierwave 3.0.7-1 MIGRATED to testing (Debian testing watch)
  • [2024-07-25] Accepted ruby-carrierwave 3.0.7-1 (source) into unstable (Aquila Macedo Costa) (signed by: Lucas Kanashiro)
  • [2023-01-27] ruby-carrierwave 1.3.2-2 MIGRATED to testing (Debian testing watch)
  • [2022-04-05] ruby-carrierwave REMOVED from testing (Debian testing watch)
  • [2021-08-16] ruby-carrierwave 1.3.2-2 MIGRATED to testing (Debian testing watch)
  • [2021-06-13] Accepted ruby-carrierwave 2.2.2-1 (source) into experimental (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2021-06-13] Accepted ruby-carrierwave 1.3.2-2 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2021-06-13] Accepted ruby-carrierwave 1.3.2-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2021-04-16] ruby-carrierwave REMOVED from testing (Debian testing watch)
  • [2020-02-04] Accepted ruby-carrierwave 2.0.2-1 (source) into experimental (Sruthi Chandran)
  • [2019-04-01] ruby-carrierwave 1.3.1-2 MIGRATED to testing (Debian testing watch)
  • [2019-03-24] Accepted ruby-carrierwave 1.3.1-2 (source) into unstable (Utkarsh Gupta) (signed by: Praveen Arimbrathodiyil)
  • [2019-02-23] Accepted ruby-carrierwave 1.3.1-1~bpo9+1 (source all) into stretch-backports (Pirate Praveen) (signed by: Abhijith PA)
  • [2019-02-01] Accepted ruby-carrierwave 1.2.3-1~bpo9+1 (source all) into stretch-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2019-01-31] ruby-carrierwave 1.3.1-1 MIGRATED to testing (Debian testing watch)
  • [2019-01-29] Accepted ruby-carrierwave 1.3.1-1 (source all) into unstable (suman) (signed by: Abhijith PA)
  • [2018-08-30] ruby-carrierwave 1.2.3-1 MIGRATED to testing (Debian testing watch)
  • [2018-08-28] Accepted ruby-carrierwave 1.2.3-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-08-15] ruby-carrierwave 1.2.2-1 MIGRATED to testing (Debian testing watch)
  • [2018-08-14] ruby-carrierwave REMOVED from testing (Debian testing watch)
  • [2018-06-17] Accepted ruby-carrierwave 1.2.2-1~bpo9+1 (source all) into stretch-backports, stretch-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-03-20] ruby-carrierwave 1.2.2-1 MIGRATED to testing (Debian testing watch)
  • [2018-03-15] Accepted ruby-carrierwave 1.2.2-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-03-05] ruby-carrierwave 1.1.0-3 MIGRATED to testing (Debian testing watch)
  • [2018-02-27] Accepted ruby-carrierwave 1.1.0-3 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-02-23] Accepted ruby-carrierwave 1.1.0-2 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2017-07-24] Accepted ruby-carrierwave 1.1.0-1 (source) into experimental (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2016-12-01] ruby-carrierwave 0.10.0+gh-4 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • buildd: logs
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.0.7-1
  • 1 bug

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing