HIGH
GHSA-p463-639r-q9g9
Dragonfly Code Injection vulnerability
Quick fix
GHSA-p463-639r-q9g9 — dragonfly: upgrade to the fixed version with the command below.
bundle update dragonflyDetails
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-1756[ADVISORY]
- https://github.com/markevans/dragonfly/commit/a8775aacf9e5c81cf11bec34b7afa7f27ddfe277[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82476[WEB]
- https://github.com/markevans/dragonfly[PACKAGE]
- https://groups.google.com/forum/?fromgroups=#!topic/dragonfly-users/3c3WIU3VQTo[WEB]
- https://web.archive.org/web/20200229103538/http://www.securityfocus.com/bid/58225[WEB]