CVE-2021-21305: Injection Vulnerability
(updated )
In CarrierWave, there is a code injection vulnerability. Attackers can craft a string that can be executed as a Ruby code.
References
Detect and mitigate CVE-2021-21305 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →