Ruby Dragonfly 漏洞列表
共找到 1 个与 Ruby Dragonfly 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2021-33564: Ruby Dragonfly <1.4.0 - Remote Code Execution POC
Ruby Dragonfly before 1.4.0 contains an argument injection vulnerability that allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.