peter bassill · operator
$ cve CVE-2021-33564 JSON

CVE-2021-33564

9.8
CRITICAL · CVSS 3.1 · EPSS 72.1% (pctl 99)

Patch early

EPSS 72.1% — above the 10% action threshold.

Description

An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS72.14% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-88
On CISA KEVno
Public exploitnone known
Published2021-05-29
Last modified2026-06-17

Affected (1)

VendorProduct
dragonfly projectdragonfly

References

→ the Explorer  ·  watch your stack  ·  NVD