dragonfly
Dragonfly is a framework that enables on-the-fly processing for any content type. It is especially suited to image handling. Its uses range from image thumbnails to standard attachments to on-demand text generation.
Activity
- Latest release
- 1mo ago
- Total releases
- 83
- Cadence
- ~39 days
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Nov 09, 2009
| Version | Released | |
|---|---|---|
1.4.2
patch
|
1.4.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.4.1
patch
|
1.4.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.4.0
minor
| ||
1.3.0
minor
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.1
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.0
minor
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.5
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.4
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.3
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.2
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.1
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.0
minor
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.12
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.11
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.10
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.9
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.8
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.7
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.6
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.5
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.4
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.3
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.2
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.1
patch
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0
major
2 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.9.15
patch
3 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev |
0.9.15
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.8.6
patch
3 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.9.14
patch
3 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev |
0.9.14
patch
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
0.9.13
patch
3 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev |
0.9.13
patch
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
0.9.12
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.9.11
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.9.10
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.9.9
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.9.8
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.9.5
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.9.4
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.9.3
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.9.2
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.8.5
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.9.1
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.8.4
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.9.0
minor
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.8.2
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.8.1
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.8.0
minor
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.7.7
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.7.6
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.7.5
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.7.4
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
0.7.2
patch
4 CVEs
CVE-2021-33473
GHSA-fj34-jhjx-xmvv
Jun 03, 2022
Arbitrary file write in dragonfly
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-33564
GHSA-j858-xp5v-f8xx
Jun 02, 2021
Dragonfly contains remote code execution vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 68 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
1.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
Fixed in
1.4.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1756
GHSA-p463-639r-q9g9
Oct 24, 2017
Dragonfly Code Injection vulnerability
High
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. Affected versions
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
+ 12 more Show less
0.8.5
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
0.8.6
0.9.13
References
Updated Apr 14, 2025 · Source: OSV.dev
CVE-2013-5671
GHSA-qrgf-jqqm-x7xv
Oct 24, 2017
Code injection in dragonfly gem
High
Affected versions
0.1.0
0.1.1
0.1.4
0.1.5
0.1.6
0.2.1
0.3.0
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
+ 46 more Show less
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.2
0.9.3
0.9.4
0.9.5
0.9.8
0.9.9
Fixed in
1.0.0
References
Updated Dec 08, 2024 · Source: OSV.dev |