Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j858-xp5v-f8xx

Опубликовано: 02 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Dragonfly contains remote code execution vulnerability

An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.

Пакеты

Наименование

dragonfly

rubygems
Затронутые версииВерсия исправления

< 1.4.0

1.4.0

EPSS

Процентиль: 100%
0.93359
Критический

9.8 Critical

CVSS3

Дефекты

CWE-88
CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.

EPSS

Процентиль: 100%
0.93359
Критический

9.8 Critical

CVSS3

Дефекты

CWE-88
CWE-94