Количество 2
Количество 2
CVE-2021-33564
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.
GHSA-j858-xp5v-f8xx
Dragonfly contains remote code execution vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-33564 An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility. | CVSS3: 9.8 | 93% Критический | больше 4 лет назад | |
GHSA-j858-xp5v-f8xx Dragonfly contains remote code execution vulnerability | CVSS3: 9.8 | 93% Критический | больше 4 лет назад |
Уязвимостей на страницу