From cf2f011774ff449b3107c422540610e698d3dc28 Mon Sep 17 00:00:00 2001 From: Mitsuhiro Shibuya Date: Sat, 23 Mar 2024 17:10:26 +0900 Subject: [PATCH] Version 3.0.7 --- CHANGELOG.md | 5 +++++ lib/carrierwave/version.rb | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index a2a34e4bb..c88b13bf3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,11 @@ This project adheres to [Semantic Versioning](http://semver.org/). ## [Unreleased] +## 3.0.7 - 2024-03-23 + +### Security +* Fix Content-Type allowlist bypass vulnerability remained (@mshibuya [00676e2](https://github.com/carrierwaveuploader/carrierwave/commit/00676e23d7f4beac12beddee6f2486b686fb7e46), [GHSA-vfmv-jfc5-pjjw](https://github.com/carrierwaveuploader/carrierwave/security/advisories/GHSA-vfmv-jfc5-pjjw)) + ## 3.0.6 - 2024-03-09 ### Fixed diff --git a/lib/carrierwave/version.rb b/lib/carrierwave/version.rb index 6140dc5cb..b17f9bc7d 100644 --- a/lib/carrierwave/version.rb +++ b/lib/carrierwave/version.rb @@ -1,3 +1,3 @@ module CarrierWave - VERSION = "3.0.6".freeze + VERSION = "3.0.7".freeze end