Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mlr0Po

#27826of 53,630
9.1Total CVSS
Vulnerabilities · 1
PT-2022-10265
9.1
2022-06-02
Unknown · Dragonfly Ruby Gem · CVE-2021-33473
**Name of the Vulnerable Software and Affected Versions** Dragonfly Ruby Gem version 1.3.0 **Description** An argument injection issue allows attackers to read and write arbitrary files when the `verify url` option is disabled. This issue is exploited via a crafted URL. **Recommendations** For Dragonfly Ruby Gem version 1.3.0, consider enabling the `verify url` option to mitigate the risk of exploitation. As a temporary workaround, restrict access to sensitive files and directories until a patch is available.