A vulnerability has been reported in Ruby on Rails Active Storage which could allow an unauthenticated remote attacker to read arbitrary files from the server and subsequently perform Remote Code Execution (RCE).
Target Audience:
All organizations and individuals using Ruby on Rails Active Storage with the libvips library enabled.
Risk Assessment:
High risk of unauthorized disclosure of sensitive files, secrets, and credentials, potentially leading to Remote Code Execution (RCE) and complete system compromise.
Impact Assessment:
High impact on Confidentiality, Integrity and Availability of the system.
The information provided herein is on "as is" basis, without warranty of any kind.