First published: Mon Jun 09 2014(Updated: )
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
rubygems/dragonfly | >=0.9<0.9.13 | 0.9.13 |
rubygems/dragonfly | >=0.7<0.8.6 | 0.8.6 |
Mark Evans Dragonfly gem | =0.7.0 | |
Mark Evans Dragonfly gem | =0.7.1 | |
Mark Evans Dragonfly gem | =0.7.2 | |
Mark Evans Dragonfly gem | =0.7.3 | |
Mark Evans Dragonfly gem | =0.7.4 | |
Mark Evans Dragonfly gem | =0.7.5 | |
Mark Evans Dragonfly gem | =0.7.6 | |
Mark Evans Dragonfly gem | =0.7.7 | |
Mark Evans Dragonfly gem | =0.8.0 | |
Mark Evans Dragonfly gem | =0.8.1 | |
Mark Evans Dragonfly gem | =0.8.2 | |
Mark Evans Dragonfly gem | =0.8.4 | |
Mark Evans Dragonfly gem | =0.8.5 | |
Mark Evans Dragonfly gem | =0.9.0 | |
Mark Evans Dragonfly gem | =0.9.1 | |
Mark Evans Dragonfly gem | =0.9.2 | |
Mark Evans Dragonfly gem | =0.9.3 | |
Mark Evans Dragonfly gem | =0.9.4 | |
Mark Evans Dragonfly gem | =0.9.5 | |
Mark Evans Dragonfly gem | =0.9.6 | |
Mark Evans Dragonfly gem | =0.9.7 | |
Mark Evans Dragonfly gem | =0.9.8 | |
Mark Evans Dragonfly gem | =0.9.9 | |
Mark Evans Dragonfly gem | =0.9.10 | |
Mark Evans Dragonfly gem | =0.9.11 | |
Mark Evans Dragonfly gem | =0.9.12 | |
Ruby on Rails |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.