VDB
Sign up
CRITICAL9.8

GHSA-j858-xp5v-f8xx

Dragonfly contains remote code execution vulnerability

Quick fix

GHSA-j858-xp5v-f8xx — dragonfly: upgrade to the fixed version with the command below.

bundle update dragonfly

Details

An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the `verify_url` option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/dragonfly
Introduced in: 0Fixed in: 1.4.0
Fixbundle update dragonfly

References