logicalparadox/dragonfly

logicalparadox/dragonfly

Releases2
Frequency2 years 3 months
Last Release
Stars4
Tiny error manager for big applications.

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
< 1.29.03.3 LOW

DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.

< 1.27.03.3 LOW

DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.

= 1.3.0, < 1.4.09.1 CRITICAL4.9 MEDIUM

An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL.

< 1.4.09.8 CRITICAL6.8 MEDIUM

An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.