Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2021-45463 Details

Description

load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://gitlab.gnome.org/GNOME/gegl/-/blob/master/docs/NEWS.adoc CVERelease NotesThird Party Advisory
https://gitlab.gnome.org/GNOME/gegl/-/commit/bfce470f0f2f37968862129d5038b35429f2909b CVEPatchThird Party Advisory
https://gitlab.gnome.org/GNOME/gegl/-/issues/298 CVEVendor Advisory
https://gitlab.gnome.org/GNOME/gimp/-/commit/e8a31ba4f2ce7e6bc34882dc27c97fba993f5868 CVEPatchThird Party Advisory
https://lists.debian.org/debian-lts-announce/2025/10/msg00021.html CVE

see all 15 references

Weakness Enumeration

CWE-IDCWE NameSource
NVD-CWE-noinfoInsufficient Information to Classify Weakness[email protected]

Affected Products

ProductVersions
gegl gegl
< 0.4.34

CPE

  • cpe:2.3:a:gegl:gegl:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
gimp gimp
< 2.10.30

CPE

  • cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
redhat enterprise linux
7.0
8.0

CPE

  • cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
fedoraproject fedora
34
35

CPE

  • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

11 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2021-45463
NVD Published Date:
Dec 23, 2021
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2021-45463 Details - Not Deferred