CVE-2021-33564
Summary
| CVE | CVE-2021-33564 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-29 14:15:00 UTC |
| Updated | 2021-06-10 15:20:00 UTC |
| Description | An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2021-33564 Argument Injection in Ruby Dragonfly | ZX Security |
MISC |
zxsecurity.co.nz |
|
| Comparing v1.3.0...v1.4.0 · markevans/dragonfly · GitHub |
MISC |
github.com |
|
| GitHub - mlr0p/CVE-2021-33564: Argument Injection in Dragonfly Ruby Gem |
MISC |
github.com |
|
| raw.githubusercontent.com/projectdiscovery/nuclei-templates/master/cves/2021/CVE-2021-3... |
MISC |
raw.githubusercontent.com |
|
| Security Issue Report · Issue #513 · markevans/dragonfly · GitHub |
MISC |
github.com |
|
| Merge branch 'better-security' · markevans/dragonfly@2539929 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690106 Free Berkeley Software Distribution (FreeBSD) Security Update for dragonfly (c9e2a1a7-caa1-11eb-904f-14dae9d5a9d2)