9.1
CVSSv3

CVE-2021-33473

Published: 02/06/2022 Updated: 27/10/2022
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows malicious users to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dragonfly project dragonfly 1.3.0