PT-2021-20207 · Dragonfly · Dragonfly
Michael Tsai
·
Published
2021-05-27
·
Updated
2021-06-10
·
CVE-2021-33564
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dragonfly gem versions prior to 1.4.0
Description
An argument injection issue allows remote attackers to read and write to arbitrary files via a crafted URL when the
verify url option is disabled, potentially leading to code execution. This occurs because the generate and process features mishandle the use of the ImageMagick convert utility.Recommendations
For Dragonfly gem versions prior to 1.4.0, update to version 1.4.0 or later to resolve the issue. As a temporary workaround, consider enabling the
verify url option to minimize the risk of exploitation. Restrict access to the generate and process features until the update is applied.Exploit
Fix
Code Injection
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dragonfly