CVE-2022-24720

image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a series of operations that are coming from unsanitized user input allows the attacker to execute shell commands. This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. The vulnerability has been fixed in version 1.12.2 of image_processing. As a workaround, users who process based on user input should always sanitize the user input by allowing only a constrained set of operations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:image_processing_project:image_processing:*:*:*:*:*:ruby:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

03 Jul 2023, 20:35

Type Values Removed Values Added
CWE CWE-20 NVD-CWE-Other

22 Feb 2023, 17:49

Type Values Removed Values Added
CWE CWE-78 CWE-20
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
References
  • (DEBIAN) https://www.debian.org/security/2022/dsa-5310 - Third Party Advisory
References (CONFIRM) https://github.com/janko/image_processing/security/advisories/GHSA-cxf7-qrc5-9446 - Exploit, Third Party Advisory (CONFIRM) https://github.com/janko/image_processing/security/advisories/GHSA-cxf7-qrc5-9446 - Exploit, Vendor Advisory

09 Mar 2022, 17:58

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 10.0
v3 : 9.8
CPE cpe:2.3:a:image_processing_project:image_processing:*:*:*:*:*:ruby:*:*
CWE CWE-78
References (MISC) https://github.com/janko/image_processing/commit/038e4574e8f4f4b636a62394e09983c71980dada - (MISC) https://github.com/janko/image_processing/commit/038e4574e8f4f4b636a62394e09983c71980dada - Patch, Third Party Advisory
References (CONFIRM) https://github.com/janko/image_processing/security/advisories/GHSA-cxf7-qrc5-9446 - (CONFIRM) https://github.com/janko/image_processing/security/advisories/GHSA-cxf7-qrc5-9446 - Exploit, Third Party Advisory

01 Mar 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-01 23:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-24720

Mitre link : CVE-2022-24720

CVE.ORG link : CVE-2022-24720


JSON object : View

Products Affected

image_processing_project

  • image_processing

debian

  • debian_linux
CWE
NVD-CWE-Other CWE-20

Improper Input Validation