The Dragonfly Project maintains a command-line package manager and system tool that, despite a focused product scope, occupies a notable position in certain deployment environments. Its observed vulnerability signal centers on improper neutralization of argument delimiters in command construction, a weakness class characteristic of tools that parse and execute user-supplied or shell-based input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dragonfly Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33564CRITICAL An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url op | May 29, 2021 | 9.8 | 79 | NO | YES |
CVE-2021-33473CRITICAL An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is ex | Jun 2, 2022 | 9.1 | 30 | NO | NO |
CVE-2005-4351MEDIUM The securelevels implementation in FreeBSD 7.0 and earlier, OpenBSD up to 3.8, DragonFly up to 1.2, and Linux up to 2.6.15 allows root users to bypass immutable settings for files | Dec 31, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dragonfly Project.
Media articles that mention a CVE ID that affects a product developed by Dragonfly Project — matched by CVE ID, not by vendor name.