Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2022-24720
Disclosure Date: March 01, 2022 (last updated February 23, 2025)
image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a series of operations that are coming from unsanitized user input allows the attacker to execute shell commands. This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. The vulnerability has been fixed in version 1.12.2 of image_processing. As a workaround, users who process based on user input should always sanitize the user input by allowing only a constrained set of operations.
0
Attacker Value
Unknown
CVE-2020-21573
Disclosure Date: November 02, 2021 (last updated February 23, 2025)
An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file.
0
Attacker Value
Unknown
CVE-2021-38623
Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service via the FAL API because of /var/transient disk consumption.
0
Attacker Value
Unknown
CVE-2005-0406
Disclosure Date: February 14, 2005 (last updated February 22, 2025)
A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.
0