{"id":"GHSA-w749-p3v6-hccq","summary":"Possible code injection vulnerability in Rails / Active Storage","details":"The Active Storage module of Rails starting with version 5.2.0 is possibly vulnerable to code injection. This issue was patched in versions 5.2.6.3, 6.0.4.7, 6.1.4.7, and 7.0.2.3. To work around this issue, applications should implement a strict allow-list on accepted transformation methods or arguments.  Additionally, a strict ImageMagick security policy will help mitigate this issue.","aliases":["CVE-2022-21831"],"modified":"2026-03-13T05:44:10.181196Z","published":"2022-03-08T21:25:54Z","related":["CVE-2022-21831"],"database_specific":{"nvd_published_at":"2022-05-26T17:15:00Z","cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-03-08T21:25:54Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21831"},{"type":"WEB","url":"https://github.com/rails/rails/commit/0a72f7d670e9aa77a0bb8584cb1411ddabb7546e"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w749-p3v6-hccq"},{"type":"PACKAGE","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2022-21831.yml"},{"type":"WEB","url":"https://groups.google.com/g/rubyonrails-security/c/n-p-W1yxatI"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/09/msg00002.html"},{"type":"WEB","url":"https://rubysec.com/advisories/CVE-2022-21831"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20221118-0001"},{"type":"WEB","url":"https://www.debian.org/security/2023/dsa-5372"}],"affected":[{"package":{"name":"activestorage","ecosystem":"RubyGems","purl":"pkg:gem/activestorage"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.2.0"},{"fixed":"5.2.6.3"}]}],"versions":["5.2.0","5.2.1","5.2.1.1","5.2.1.rc1","5.2.2","5.2.2.1","5.2.2.rc1","5.2.3","5.2.3.rc1","5.2.4","5.2.4.1","5.2.4.2","5.2.4.3","5.2.4.4","5.2.4.5","5.2.4.6","5.2.4.rc1","5.2.5","5.2.6","5.2.6.1","5.2.6.2"],"database_specific":{"last_known_affected_version_range":"\u003c= 5.2.6.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-w749-p3v6-hccq/GHSA-w749-p3v6-hccq.json"}},{"package":{"name":"activestorage","ecosystem":"RubyGems","purl":"pkg:gem/activestorage"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.0.4.7"}]}],"versions":["6.0.0","6.0.1","6.0.1.rc1","6.0.2","6.0.2.1","6.0.2.2","6.0.2.rc1","6.0.2.rc2","6.0.3","6.0.3.1","6.0.3.2","6.0.3.3","6.0.3.4","6.0.3.5","6.0.3.6","6.0.3.7","6.0.3.rc1","6.0.4","6.0.4.1","6.0.4.2","6.0.4.3","6.0.4.4","6.0.4.5","6.0.4.6"],"database_specific":{"last_known_affected_version_range":"\u003c= 6.0.4.6","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-w749-p3v6-hccq/GHSA-w749-p3v6-hccq.json"}},{"package":{"name":"activestorage","ecosystem":"RubyGems","purl":"pkg:gem/activestorage"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.1.0"},{"fixed":"6.1.4.7"}]}],"versions":["6.1.0","6.1.1","6.1.2","6.1.2.1","6.1.3","6.1.3.1","6.1.3.2","6.1.4","6.1.4.1","6.1.4.2","6.1.4.3","6.1.4.4","6.1.4.5","6.1.4.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-w749-p3v6-hccq/GHSA-w749-p3v6-hccq.json","last_known_affected_version_range":"\u003c= 6.1.4.6"}},{"package":{"name":"activestorage","ecosystem":"RubyGems","purl":"pkg:gem/activestorage"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.0.2.3"}]}],"versions":["7.0.0","7.0.1","7.0.2","7.0.2.1","7.0.2.2"],"database_specific":{"last_known_affected_version_range":"\u003c= 7.0.2.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-w749-p3v6-hccq/GHSA-w749-p3v6-hccq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}