GHSA-qrgf-jqqm-x7xv

Suggest an improvement
Source
https://github.com/advisories/GHSA-qrgf-jqqm-x7xv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-qrgf-jqqm-x7xv/GHSA-qrgf-jqqm-x7xv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qrgf-jqqm-x7xv
Aliases
  • CVE-2013-5671
Published
2017-10-24T18:33:37Z
Modified
2024-12-08T05:34:08.990355Z
Summary
Code injection in dragonfly gem
Details

lib/dragonfly/imagemagickutils.rb in the fog-dragonfly gem 0.8.2 for Ruby allows remote attackers to execute arbitrary commands via unspecified vectors.

Database specific
{
    "nvd_published_at": "2014-05-12T14:55:05Z",
    "cwe_ids": [
        "CWE-74"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:52:41Z"
}
References

Affected packages

RubyGems / dragonfly

Package

Name
dragonfly
Purl
pkg:gem/dragonfly

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.0

Affected versions

0.*

0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15

RubyGems / fog-dragonfly

Package

Name
fog-dragonfly
Purl
pkg:gem/fog-dragonfly

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.9.15

Affected versions

0.*

0.8.1
0.8.2