CVE Vulnerabilities

CVE-2021-45463

Published: Dec 23, 2021 | Modified: Nov 03, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

Affected Software

NameVendorStart VersionEnd Version
GeglGegl*0.4.34 (excluding)
Red Hat Enterprise Linux 7RedHatgegl-0:0.2.0-19.el7_9.1*
Red Hat Enterprise Linux 8RedHatgegl04-0:0.4.4-6.el8_5.2*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatgegl04-0:0.4.4-6.el8_2.1*
Red Hat Enterprise Linux 8.4 Extended Update SupportRedHatgegl04-0:0.4.4-6.el8_4.1*
GeglUbuntubionic*
GeglUbuntudevel*
GeglUbuntuesm-apps/bionic*
GeglUbuntuesm-apps/focal*
GeglUbuntuesm-apps/jammy*
GeglUbuntuesm-apps/noble*
GeglUbuntuesm-apps/xenial*
GeglUbuntufocal*
GeglUbuntuhirsute*
GeglUbuntuimpish*
GeglUbuntujammy*
GeglUbuntukinetic*
GeglUbuntulunar*
GeglUbuntumantic*
GeglUbuntunoble*
GeglUbuntuoracular*
GeglUbuntuplucky*
GeglUbuntutrusty*
GeglUbuntutrusty/esm*
GeglUbuntuupstream*
GeglUbuntuxenial*

References