CVE-2022-21831
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 3.0%
exploitation probability
3.0%top 13% of all CVEs
observed exploitation
nono source reports it
A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
Affected products
n/a · https://github.com/rails/rails