Upgrade mini_magick to fix CVE-2019-13574
More information
high severity
Vulnerable versions: < 4.9.4
Patched version: 4.9.4
In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote
image filename could cause remote command execution because Image.open
input is directly passed to Kernel#open, which accepts a '|' character
followed by a command.