CRITICAL9.8
GHSA-j858-xp5v-f8xx
Dragonfly contains remote code execution vulnerability
Quick fix
GHSA-j858-xp5v-f8xx — dragonfly: upgrade to the fixed version with the command below.
bundle update dragonflyDetails
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the `verify_url` option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-33564[ADVISORY]
- https://github.com/markevans/dragonfly/issues/513[WEB]
- https://github.com/markevans/dragonfly/commit/25399297bb457f7fcf8e3f91e85945b255b111b5[WEB]
- https://github.com/advisories/GHSA-j858-xp5v-f8xx[ADVISORY]
- https://github.com/markevans/dragonfly/compare/v1.3.0...v1.4.0[WEB]
- https://github.com/mlr0p/CVE-2021-33564[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/dragonfly/CVE-2021-33564.yml[WEB]
- https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/master/cves/2021/CVE-2021-33564.yaml[WEB]
- https://zxsecurity.co.nz/research/argunment-injection-ruby-dragonfly[WEB]