| Version | Supported |
|---|---|
| 2.x | Yes |
| 1.x | No |
Report vulnerabilities privately through GitHub private vulnerability reporting for this repository.
If you cannot use GitHub reporting, contact Cloudinary support at support.cloudinary.com and mark the ticket as a security issue.
Use these private channels for anything security-sensitive; public GitHub issues are for regular bugs and feature requests.
- The affected gem version and Ruby version (and Rails version, if relevant).
- A minimal reproduction or proof of concept.
- The impact you believe the issue has (for example: credential exposure, signature bypass, request forgery).
- Any suggested remediation, if you have one.
- We acknowledge reports and keep you informed while the issue is investigated.
- Fixes are released as patched gem versions; the changelog notes security-relevant changes without disclosing exploit details before users can upgrade.
- Please give us reasonable time to release a fix before public disclosure.
- Your
api_secretis a server-side credential. Keep it on your server; browsers, mobile binaries, and repositories should only ever hold delivery URLs or short-lived signatures. - Provide credentials through the
CLOUDINARY_URLenvironment variable rather than hardcoding them. In Rails, use encrypted credentials — do not commitapi_keyorapi_secrettoconfig/cloudinary.yml. - For uploads initiated from a browser or mobile app, generate the signature on your server. See docs/sign-browser-upload.md.
- For unsigned uploads, use a deliberately restricted unsigned upload preset (md).
- Do not log whole exception or response objects from Admin and Upload API calls — request payloads can contain your
api_key. Log the message. - Cloudinary platform security documentation: https://cloudinary.com/documentation/solution_overview#security