Description
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
Remediation
References
Related Vulnerabilities
MediaWiki Other Vulnerability (CVE-2004-2187)
GlassFish CVE-2010-2397 Vulnerability (CVE-2010-2397)
markdown-it Inefficient Regular Expression Complexity Vulnerability (CVE-2015-10005)
WordPress Plugin Social Sharing-Sassy Social Share Cross-Site Scripting (3.3.44)
Craft CMS Missing Encryption of Sensitive Data Vulnerability (CVE-2022-37783)