VDB
Sign up
HIGH

GHSA-w754-gq8r-pf5f

MiniMagick Gem for Ruby URI Handling Arbitrary Command Injection

Quick fix

GHSA-w754-gq8r-pf5f — mini_magick: upgrade to the fixed version with the command below.

bundle update mini_magick

Details

`lib/mini_magick.rb` in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/mini_magick
Introduced in: 0Fixed in: 3.6.0
Fixbundle update mini_magick

References