7 ms·
This was fixed in 6.0.0.beta3, 5.2.2.1, 5.1.6.2, 5.0.7.2, 4.2.11.1 one week ago. https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-relea
by aboutruby 8y ago
This was fixed in 6.0.0.beta3, 5.2.2.1, 5.1.6.2, 5.0.7.2, 4.2.11.1 one week ago.
https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/ https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6...
The two HN posts didn't get many upvotes though: https://hn.algolia.com/?query=https:%2F%2Fweblog.rubyonrails.org%2F2019%2F3%2F13%2FRails-4-2-5-1-5-1-6-2-have-been-released%2F&sort=byPopularity&prefix&page=0&dateRange=all&type=story https://hn.algolia.com/?query=https:%2F%2Fweblog.rubyonrails...
Admittedly there is probably a lot of applications out there running outdated versions.
edit: Kind of surprising this gets upvoted while we rarely see things from exploit-db / fulldisclosure
- anitil 8y agoI'm a bit confused here, perhaps because I don't really understand Rails (possibly also the HTML spec). I was under the impression the 'Accept:' header is a list of media types, so why would that be making filesystem calls? Or does Rails implicitly organize assets in a filesystem structure (something like ~/assets/audio or ~/assets/text)?
- tptacek 8y agoBecause the media types are parsed and used to select layout templates (layout.html.erb vs layout.xml.erb, etc).
- anitil 8y agoAaaah Thankyou!
- Something1234 8y agoSo why wouldn't we just have a mapping between mime-types and extensions for look ups? Why bother examining the accept header beyond splitting and searching within the list? Like in such a way that we're opening arbitrary files with it?
- tptacek 8y agoThat's essentially what the patch does; the "symbol" call only resolves for known-good mime types.
- Something1234 8y agoWhere would this code be in the rails code base? I usually don't touch ruby. I'm mildly curious what was there originally.
- tptacek 8y agoIn the template resolver in ActionView. It's spread over multiple files and a bit hard to follow, which no doubt contributed to the problem.
- lostapathy 8y agoUnfortunately a lot of rails internals are like this :(.
- archgoon 8y agoThe technical analysis (from the article), complete with a step by step trace walkthrough, is here: https://chybeta.github.io/2019/03/16/Analysis-for%E3%80%90CVE-2019-5418%E3%80%91File-Content-Disclosure-on-Rails/ https://chybeta.github.io/2019/03/16/Analysis-for%E3%80%90CV... Also, if interested, direct link to patch fix: https://github.com/rails/rails/commit/f4c70c2222180b8d9d924f00af0c7fd632e26715 https://github.com/rails/rails/commit/f4c70c2222180b8d9d924f...
- anitil 8y agoThanks for that, I was missing the step that assets are named $filename.$mime-type.erb in Rails. I was missing the high-level view
- deleted 8y ago[deleted]
- xtagon 8y agoSo it's a problem in ActionView, and fixed in 5.1.6.2...then why does the changelog for ActionView for 5.1.6.2 say "No changes"? https://github.com/rails/rails/blob/5-1-stable/actionview/CHANGELOG.md#rails-5162-march-11-2019 https://github.com/rails/rails/blob/5-1-stable/actionview/CH...
- aboutruby 8y agoIt's actually in ActionPack / Railties but I've raised the issue: https://github.com/rails/rails/issues/35702 https://github.com/rails/rails/issues/35702