{"api_version":"v1","generated_at":"2026-10-09T11:15:00+00:00","product":{"cve_count":5,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-carrierwaveuploader-carrierwave-67fa748f9581","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"carrierwave","next_cursor":null,"observations":[{"affected":"< 2.2.7; >= 3.0.0.rc, < 3.1.3","affected_versions_present":true,"cve_id":"CVE-2026-44587","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44587","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-17T18:12:37.182Z","patch_url":"https://github.com/carrierwaveuploader/carrierwave/commit/21221cc6e260633f7da78c6133a88666a5529d27","primary_source":"","published":"2026-06-16T23:10:43.665Z"},{"affected":">= 3.0.0, < 3.0.7; < 2.2.6","affected_versions_present":true,"cve_id":"CVE-2024-29034","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-29034","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T01:03:51.518Z","patch_url":"https://github.com/carrierwaveuploader/carrierwave/security/advisories/GHSA-vfmv-jfc5-pjjw","primary_source":"","published":"2024-03-24T19:27:35.996Z"},{"affected":">= 2.2.0, < 2.2.5; >= 3.0.0, < 3.0.5","affected_versions_present":true,"cve_id":"CVE-2023-49090","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-49090","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-10-11T17:55:40.314Z","patch_url":"https://github.com/carrierwaveuploader/carrierwave/commit/39b282db5c1303899b3d3381ce8a837840f983b5","primary_source":"","published":"2023-11-29T14:38:52.195Z"},{"affected":"< 1.3.2; >= 2.0.0, < 2.1.1","affected_versions_present":true,"cve_id":"CVE-2021-21305","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21305","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:09:15.001Z","patch_url":"https://github.com/carrierwaveuploader/carrierwave/commit/387116f5c72efa42bc3938d946b4c8d2f22181b7","primary_source":"","published":"2021-02-08T19:20:14.000Z"},{"affected":"< 1.3.2; >= 2.0.0, < 2.1.1","affected_versions_present":true,"cve_id":"CVE-2021-21288","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21288","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:09:15.747Z","patch_url":"https://github.com/carrierwaveuploader/carrierwave/commit/012702eb3ba1663452aa025831caa304d1a665c0","primary_source":"","published":"2021-02-08T19:15:16.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"carrierwaveuploader"}}
