S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-33564 Scanner

Detects 'Argument Injection' vulnerability in Dragonfly  (open source project) affects v. before 1.4.0.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-33564
9.8
CVSS

An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Dragonfly is a Ruby gem that is used for on-the-fly processing and uploading of images. It provides a simple interface to crop, resize, and animate images. It can handle all input and output file types, making it a versatile tool. It also supports integrations with popular data storage services like Amazon S3 and Rackspace, which allows users to store and retrieve images easily.

CVE-2021-33564 is a vulnerability detected in the Dragonfly gem before version 1.4.0. It is an argument injection vulnerability that is caused due to the mishandling of the ImageMagick convert utility in the generate and process features. When the "verify_url" option is disabled, remote attackers can exploit this vulnerability to read and write arbitrary files, which could lead to code execution.

If this vulnerability is exploited, attackers can gain unauthorized access to sensitive files and data. They can upload and execute arbitrary code on systems and servers, which can lead to system crashes, data breaches, and theft of intellectual property. These attacks can also result in the disruption of critical business operations, causing significant financial and reputational damages to organizations.

In conclusion, digital asset security is crucial for organizations that want to protect their intellectual property and sensitive data. With s4e.io's pro features, users can easily and quickly learn about vulnerabilities in their digital assets. These pro features provide customized security alerts and comprehensive reports that allow users to take proactive measures to prevent attacks. By being aware of the latest vulnerabilities and taking precautionary measures, organizations can ensure the safety and integrity of their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Upgrade the Dragonfly gem to version 1.4.0 or later, which contains a fix for this vulnerability.
  • Enable the "verify_url" option in the Dragonfly configuration. This option allows only valid URLs to be processed by Dragonfly, which can prevent unauthorized access to files.
  • Configure ImageMagick to use a policy file that restricts access to specific commands and options. This can prevent attackers from executing malicious commands using the convert utility.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.