Ruby Dragonfly before 1.4.0 contains an argument injection vulnerability that allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.
id: CVE-2021-33564
info:
name: Ruby Dragonfly <1.4.0 - Remote Code Execution
author: 0xsapra
...