CVE-2022-21831
published 2022-05-26CVE-2022-21831: A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.74%
84.5th percentile
A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | rails | < rails 2:6.1.4.7+dfsg-1 (bookworm) | rails 2:6.1.4.7+dfsg-1 (bookworm) |
| https | github.com_rails_rails | — | — |
| rails | activestorage | >= 5.2.0 < 5.2.6.3 | 5.2.6.3 |
| rails | activestorage | >= 6.0.0 < 6.0.4.7 | 6.0.4.7 |
| rails | activestorage | >= 6.1.0 < 6.1.4.7 | 6.1.4.7 |
| rails | activestorage | >= 7.0.0 < 7.0.2.3 | 7.0.2.3 |
| rubyonrails | active_storage | >= 5.2.0 < 5.2.6.3 | 5.2.6.3 |
| rubyonrails | active_storage | >= 6.0.0 < 6.0.4.7 | 6.0.4.7 |
| rubyonrails | active_storage | >= 6.1.0 < 6.1.4.7 | 6.1.4.7 |
| rubyonrails | active_storage | >= 7.0.0 < 7.0.2.3 | 7.0.2.3 |
| rubyonrails | rails | >= 0 < 2:6.0.3.7+dfsg-2+deb11u1 | 2:6.0.3.7+dfsg-2+deb11u1 |
| rubyonrails | rails | >= 0 < 2:6.1.4.7+dfsg-1 | 2:6.1.4.7+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:6.1.4.7+dfsg-1 | 2:6.1.4.7+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:6.1.4.7+dfsg-1 | 2:6.1.4.7+dfsg-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-21831: A code injection vulnerability exists in the Active Storage >= v5
osv·2022-05-26·CVSS 9.8
CVE-2022-21831 [CRITICAL] CVE-2022-21831: A code injection vulnerability exists in the Active Storage >= v5
A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
GHSA
Possible code injection vulnerability in Rails / Active Storage
ghsa·2022-03-08
CVE-2022-21831 [CRITICAL] CWE-94 Possible code injection vulnerability in Rails / Active Storage
Possible code injection vulnerability in Rails / Active Storage
The Active Storage module of Rails starting with version 5.2.0 is possibly vulnerable to code injection. This issue was patched in versions 5.2.6.3, 6.0.4.7, 6.1.4.7, and 7.0.2.3. To work around this issue, applications should implement a strict allow-list on accepted transformation methods or arguments. Additionally, a strict ImageMagick security policy will help mitigate this issue.
OSV
Possible code injection vulnerability in Rails / Active Storage
osv·2022-03-08
CVE-2022-21831 [CRITICAL] Possible code injection vulnerability in Rails / Active Storage
Possible code injection vulnerability in Rails / Active Storage
The Active Storage module of Rails starting with version 5.2.0 is possibly vulnerable to code injection. This issue was patched in versions 5.2.6.3, 6.0.4.7, 6.1.4.7, and 7.0.2.3. To work around this issue, applications should implement a strict allow-list on accepted transformation methods or arguments. Additionally, a strict ImageMagick security policy will help mitigate this issue.
Red Hat
rubygem-activestorage: Code injection vulnerability in ActiveStorage
vendor_redhat·2022-03-08·CVSS 9.8
CVE-2022-21831 [CRITICAL] CWE-94 rubygem-activestorage: Code injection vulnerability in ActiveStorage
rubygem-activestorage: Code injection vulnerability in ActiveStorage
A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
A flaw was found in the Active Storage module of Rails, where the transformation method or its arguments for image_processing are not trusted arbitrary input. This flaw allows an attacker to inject code in Rails.
Mitigation: To work around this issue, applications should implement a strict allow-list on accepted transformation methods or arguments. Additionally, a strict image magick security policy will help mitigate this issue:
https://imagemagick.org/script/security-policy.php
Package: tfm-ror52-rubygem-rails (Red Hat Satellite 6) - Not affected
Debian
CVE-2022-21831: rails - A code injection vulnerability exists in the Active Storage >= v5.2.0 that could...
vendor_debian·2022·CVSS 9.8
CVE-2022-21831 [CRITICAL] CVE-2022-21831: rails - A code injection vulnerability exists in the Active Storage >= v5.2.0 that could...
A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
Scope: local
bookworm: resolved (fixed in 2:6.1.4.7+dfsg-1)
bullseye: resolved (fixed in 2:6.0.3.7+dfsg-2+deb11u1)
forky: resolved (fixed in 2:6.1.4.7+dfsg-1)
sid: resolved (fixed in 2:6.1.4.7+dfsg-1)
trixie: resolved (fixed in 2:6.1.4.7+dfsg-1)
No detection rules found.
No public exploits indexed.
https://github.com/advisories/GHSA-w749-p3v6-hccqhttps://lists.debian.org/debian-lts-announce/2022/09/msg00002.htmlhttps://security.netapp.com/advisory/ntap-20221118-0001/https://www.debian.org/security/2023/dsa-5372https://github.com/advisories/GHSA-w749-p3v6-hccqhttps://lists.debian.org/debian-lts-announce/2022/09/msg00002.htmlhttps://security.netapp.com/advisory/ntap-20221118-0001/https://www.debian.org/security/2023/dsa-5372
2022-05-26
Published