HIGH
GHSA-qrgf-jqqm-x7xv
Code injection in dragonfly gem
Quick fix
GHSA-qrgf-jqqm-x7xv — dragonfly: upgrade to the fixed version with the command below.
bundle update dragonflyDetails
`lib/dragonfly/imagemagickutils.rb` in the fog-dragonfly gem 0.8.2 for Ruby allows remote attackers to execute arbitrary commands via unspecified vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
RubyGems/fog-dragonfly
Introduced in:
0No fixed version published yet for fog-dragonfly (bundler). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-5671[ADVISORY]
- https://github.com/markevans/dragonfly/issues/520[WEB]
- https://github.com/github/advisory-database/pull/486[WEB]
- https://github.com/markevans/dragonfly[PACKAGE]
- https://web.archive.org/web/20201208033320/http://www.vapid.dhs.org/advisories/fog-dragonfly-0.8.2-cmd-inj.html[WEB]
- http://seclists.org/fulldisclosure/2013/Sep/18[WEB]
- http://seclists.org/oss-sec/2013/q3/526[WEB]
- http://seclists.org/oss-sec/2013/q3/528[WEB]