Описание
Dragonfly Code Injection vulnerability
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-1756
- https://github.com/markevans/dragonfly/commit/a8775aacf9e5c81cf11bec34b7afa7f27ddfe277
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82476
- https://groups.google.com/forum/?fromgroups=#!topic/dragonfly-users/3c3WIU3VQTo
- https://web.archive.org/web/20200229103538/http://www.securityfocus.com/bid/58225
Пакеты
Наименование
dragonfly
rubygems
Затронутые версииВерсия исправления
>= 0.7, < 0.8.6
0.8.6
Наименование
dragonfly
rubygems
Затронутые версииВерсия исправления
>= 0.9, < 0.9.13
0.9.13
Связанные уязвимости
nvd
больше 11 лет назад
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request.