Dragonfly contains remote code execution vulnerability
Critical severity
GitHub Reviewed
Published
Jun 2, 2021
to the GitHub Advisory Database
•
Updated Aug 25, 2023
Description
Published by the National Vulnerability Database
May 29, 2021
Reviewed
Jun 1, 2021
Published to the GitHub Advisory Database
Jun 2, 2021
Last updated
Aug 25, 2023
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the
verify_url
option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.References