VYPR

RubyGems package

shrine

pkg:gem/shrine

Vulnerabilities (1)

  • CVE-2020-15237Oct 5, 2020
    affected < 3.3.0fixed 3.3.0

    In Shrine before version 3.3.0, when using the `derivation_endpoint` plugin, it's possible for the attacker to use a timing attack to guess the signature of the derivation URL. The problem has been fixed by comparing sent and calculated signature in constant time, using `Rack::Ut