-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the unhandled exception in image dimension extraction logic. The patch adds a rescue clause to the dimension assignment line (res['dimension'] = ... rescue '0x0'), specifically addressing the lack of error handling around MiniMagick's image parsing. This code path is directly tied to media upload processing, matching the vulnerability description of SVG-triggered crashes.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| camaleon_cms | rubygems | >= 2.0.1, < 2.6.0.1 | 2.6.0.1 |
Ongoing coverage of React2Shell