Dragonfly Project
dragonfly_project
2 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dragonfly Project 1Dragonfly Jun 17, 2026 Jun 2, 2022 N/A· v4 9.1 CRITICAL· v3 4.9 MEDIUM· v2 An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL. |
1Dragonfly Project 1Dragonfly Jun 17, 2026 May 29, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code...Show more |