Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 RubyGems

Possible code injection vulnerability in Rails / Active Storage

GHSA-w749-p3v6-hccq · CVE-2022-21831

Published · Modified

Description

The Active Storage module of Rails starting with version 5.2.0 is possibly vulnerable to code injection. This issue was patched in versions 5.2.6.3, 6.0.4.7, 6.1.4.7, and 7.0.2.3. To work around this issue, applications should implement a strict allow-list on accepted transformation methods or arguments. Additionally, a strict ImageMagick security policy will help mitigate this issue.

Ready to move

Start Securing

Free, no credit card | First findings in minutes