image_processing
Web-friendly image processing macros for libvips and ImageMagick
Activity
- Latest release
- 1w ago
- Total releases
- 49
- Cadence
- ~20 days
- Last 12 months
- 5
Reach
- Stars
- 960
Details
- License
- MIT
- First release
- Oct 03, 2015
| Version | Released | |
|---|---|---|
2.1.0
minor
| ||
2.0.3
patch
| ||
2.0.2
patch
| ||
2.0.1
patch
| ||
2.0.0
major
| ||
1.14.0
minor
|
1.14.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.13.0
minor
|
1.13.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.12.2
patch
|
1.12.2
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.12.1
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.12.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.12.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.12.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.11.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.11.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.10.3
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.10.3
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.10.2
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.10.2
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.10.1
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.10.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.10.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.10.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.9.3
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.9.3
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.9.2
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.9.2
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.9.1
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.9.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.9.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.9.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.8.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.8.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.7.1
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.7.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
1.7.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.7.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.6.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.6.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.5.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.5.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.4.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.4.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.3.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.3.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.2.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.2.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.1.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.1.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.0.0
major
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0
major
Dependencies (7)
Changelog
Compare changes
|
|
0.11.2
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.11.2
patch
Dependencies (7)
Changelog
Compare changes
|
|
0.11.1
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.10.3
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.10.2
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.10.1
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.10.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.4.5
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.4.2
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.4.3
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.4.4
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.5
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.4
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.3
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.2
patch
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.1
initial
1 CVE
CVE-2022-24720
GHSA-cxf7-qrc5-9446
Mar 01, 2022
Remote shell execution vulnerability in image_processing
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactWhen using the
This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. PatchesThe vulnerability has been fixed in version 1.12.2 of image_processing. WorkaroundsIf you're processing based on user input, it's highly recommended that you always sanitize the user input, by allowing only a constrained set of operations. For example:
Affected versions
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.11.1
0.11.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
+ 29 more Show less
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.9.0
1.0.0
1.1.0
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.12.0
1.12.1
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.12.2
References
Updated Nov 08, 2023 · Source: OSV.dev |