VDB
Sign up
CRITICAL9.8

GHSA-w749-p3v6-hccq

Possible code injection vulnerability in Rails / Active Storage

Quick fix

GHSA-w749-p3v6-hccq — activestorage: upgrade to the fixed version with the command below.

bundle update activestorage

Details

The Active Storage module of Rails starting with version 5.2.0 is possibly vulnerable to code injection. This issue was patched in versions 5.2.6.3, 6.0.4.7, 6.1.4.7, and 7.0.2.3. To work around this issue, applications should implement a strict allow-list on accepted transformation methods or arguments. Additionally, a strict ImageMagick security policy will help mitigate this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activestorage
Introduced in: 5.2.0Fixed in: 5.2.6.3
Fixbundle update activestorage
RubyGems/activestorage
Introduced in: 6.0.0Fixed in: 6.0.4.7
Fixbundle update activestorage
RubyGems/activestorage
Introduced in: 6.1.0Fixed in: 6.1.4.7
Fixbundle update activestorage
RubyGems/activestorage
Introduced in: 7.0.0Fixed in: 7.0.2.3
Fixbundle update activestorage

References