CVE-2021-33564
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.
Una vulnerabilidad de inyección de argumentos en Dragonfly gem versiones anteriores a 1.4.0 para Ruby, permite a atacantes remotos leer y escribir en archivos arbitrarios por medio de una URL diseñada cuando la opción verify_url está deshabilitada. Esto puede conllevar a una ejecución de código. El problema ocurre porque las funcionalidades generate y process no usan apropiadamente la utilidad de conversión de ImageMagick
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-05-24 CVE Reserved
- 2021-05-27 First Exploit
- 2021-05-29 CVE Published
- 2024-05-17 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://github.com/markevans/dragonfly/issues/513 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://github.com/markevans/dragonfly/commit/25399297bb457f7fcf8e3f91e85945b255b111b5 | 2021-06-10 | |
https://github.com/markevans/dragonfly/compare/v1.3.0...v1.4.0 | 2021-06-10 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dragonfly Project Search vendor "Dragonfly Project" | Dragonfly Search vendor "Dragonfly Project" for product "Dragonfly" | < 1.4.0 Search vendor "Dragonfly Project" for product "Dragonfly" and version " < 1.4.0" | ruby |
Affected
|