CRITICAL9.1
GHSA-fj34-jhjx-xmvv
Arbitrary file write in dragonfly
Quick fix
GHSA-fj34-jhjx-xmvv — dragonfly: upgrade to the fixed version with the command below.
bundle update dragonflyDetails
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-33473[ADVISORY]
- https://github.com/markevans/dragonfly/issues/513[WEB]
- https://github.com/markevans/dragonfly/commit/25399297bb457f7fcf8e3f91e85945b255b111b5[WEB]
- https://github.com/markevans/dragonfly[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/dragonfly/CVE-2021-33473.yml[WEB]
- https://security.netapp.com/advisory/ntap-20220715-0004[WEB]