← Voltar para CVEs
CVE-2022-24720
CRITICAL9.8
Descricao
image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a series of operations that are coming from unsanitized user input allows the attacker to execute shell commands. This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. The vulnerability has been fixed in version 1.12.2 of image_processing. As a workaround, users who process based on user input should always sanitize the user input by allowing only a constrained set of operations.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado3/1/2022
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
debian:debian_linuximage_processing_project:image_processing
Fraquezas (CWE)
CWE-20
Referencias
https://github.com/janko/image_processing/commit/038e4574e8f4f4b636a62394e09983c71980dada(security-advisories@github.com)
https://github.com/janko/image_processing/security/advisories/GHSA-cxf7-qrc5-9446(security-advisories@github.com)
https://www.debian.org/security/2022/dsa-5310(security-advisories@github.com)
https://github.com/janko/image_processing/commit/038e4574e8f4f4b636a62394e09983c71980dada(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/janko/image_processing/security/advisories/GHSA-cxf7-qrc5-9446(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2022/dsa-5310(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.