A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2022-05-26T00:00:00
Updated: 2024-08-03T02:53:36.300Z
Reserved: 2021-12-10T00:00:00
Link: CVE-2022-21831
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-05-26T17:15:09.017
Modified: 2024-11-21T06:45:31.367
Link: CVE-2022-21831
Redhat