CVE-2013-2616
MiniMagick Gem for Ruby URI Handling Arbitrary Command Injection
EPSS 3.6%
Description
`lib/mini_magick.rb` in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
How to fix CVE-2013-2616
To remediate CVE-2013-2616, upgrade the affected package to a fixed version below.
- RubyGems/mini_magick—upgrade to 3.6.0 or later
Is CVE-2013-2616 being exploited?
Low — EPSS is 3.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.6.0