#rubysec — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #rubysec, aggregated by home.social.
-
Just released bundler-audit 0.9.3, which officially adds support for Ruby 3.4, 3.5, 4.0, and Bundler 4.x.
https://github.com/rubysec/bundler-audit/releases/tag/v0.9.3
https://github.com/rubysec/bundler-audit#readme -
Just released bundler-audit 0.9.3, which officially adds support for Ruby 3.4, 3.5, 4.0, and Bundler 4.x.
https://github.com/rubysec/bundler-audit/releases/tag/v0.9.3
https://github.com/rubysec/bundler-audit#readme -
PSA: supply chain attacks (aka forking popular gems, changing the name slightly, and adding malicious code) are starting to show up on https://rubygems.org more often. Be cautious when adding a new gem to your project. Check who the author is, check the GitHub repository, look at the commit history, etc.
https://socket.dev/blog/malicious-ruby-gems-exfiltrate-telegram-tokens-and-messages-following-vietnam-ban -
PSA: supply chain attacks (aka forking popular gems, changing the name slightly, and adding malicious code) are starting to show up on https://rubygems.org more often. Be cautious when adding a new gem to your project. Check who the author is, check the GitHub repository, look at the commit history, etc.
https://socket.dev/blog/malicious-ruby-gems-exfiltrate-telegram-tokens-and-messages-following-vietnam-ban -
Liking the new "maintainer" role for rubygem maintainers.
https://blog.rubygems.org/2024/11/07/maintainer-role.html -
Liking the new "maintainer" role for rubygem maintainers.
https://blog.rubygems.org/2024/11/07/maintainer-role.html -
💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it safe in production?
If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!
-
Heads Up Everyone. An unpatched CVE for Sinatra was just added to ruby-advisory-db. Currently all versions are affected. Impact is a possible Open Redirect.
https://github.com/advisories/GHSA-hxx2-7vcw-mqr3
#ruby #sinatra #rubysec -
Heads Up Everyone. An unpatched CVE for Sinatra was just added to ruby-advisory-db. Currently all versions are affected. Impact is a possible Open Redirect.
https://github.com/advisories/GHSA-hxx2-7vcw-mqr3
#ruby #sinatra #rubysec -
Heads Up Everyone: there's an not-yet-patched-and-released security vulnerability in WEBrick. This is going to be added to ruby-advisory-db shortly, so don't be surprised if webrick starts getting flagged; although I'm guessing it's probably only in your Gemfile.lock due to some other gem pulling it in.
Update: webrick 1.8.2 has now been released.
-
Heads Up Everyone: there's an not-yet-patched-and-released security vulnerability in WEBrick. This is going to be added to ruby-advisory-db shortly, so don't be surprised if webrick starts getting flagged; although I'm guessing it's probably only in your Gemfile.lock due to some other gem pulling it in.
Update: webrick 1.8.2 has now been released.
-
Released bundler-audit 0.9.2 fixing a few minor issues.
https://github.com/rubysec/bundler-audit/releases/tag/v0.9.2
https://github.com/rubysec/bundler-audit#readme -
Released bundler-audit 0.9.2 fixing a few minor issues.
https://github.com/rubysec/bundler-audit/releases/tag/v0.9.2
https://github.com/rubysec/bundler-audit#readme -
Thank you to @havenwood for updating the ruby-versions repo for CVE-2024-27282! ruby-install users, please upgrade your ruby versions!
ruby-install --update
ruby-install ruby-3.0.7
ruby-install ruby-3.1.5
ruby-install ruby-3.2.4
ruby-install ruby-3.3.1https://www.ruby-lang.org/en/news/2024/04/23/arbitrary-memory-address-read-regexp-cve-2024-27282/
#ruby #rubysec #cve #cve_2024_2782 #cve20242782 -
Thank you to @havenwood for updating the ruby-versions repo for CVE-2024-27282! ruby-install users, please upgrade your ruby versions!
ruby-install --update
ruby-install ruby-3.0.7
ruby-install ruby-3.1.5
ruby-install ruby-3.2.4
ruby-install ruby-3.3.1https://www.ruby-lang.org/en/news/2024/04/23/arbitrary-memory-address-read-regexp-cve-2024-27282/
#ruby #rubysec #cve #cve_2024_2782 #cve20242782 -
PyPI temporarily halted new user signups in response to a surge in malicious typosquating packages. I suspect attackers will turn their sights to NPM and rubygems.org next.
https://arstechnica.com/security/2024/03/pypi-halted-new-users-and-projects-while-it-fended-off-supply-chain-attack/
#rubygems #rubysec -
PyPI temporarily halted new user signups in response to a surge in malicious typosquating packages. I suspect attackers will turn their sights to NPM and rubygems.org next.
https://arstechnica.com/security/2024/03/pypi-halted-new-users-and-projects-while-it-fended-off-supply-chain-attack/
#rubygems #rubysec -
💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it safe in production?
-
💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it safe in production?
If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!
-
💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it safe in production?
If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!
-
💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it safe in production?
If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!
-
💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it secure enough?
If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!
-
💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it secure enough?
If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!
-
So it appears that the jquery-ui-rails gem is abandoned? Are there any plans to find a new maintainer, or ping the author? The gem is currently vulnerable to multiple old XSSs from jQuery 1.30.0.
https://github.com/jquery-ui-rails/jquery-ui-rails/issues/140
https://nvd.nist.gov/vuln/detail/CVE-2022-31160 -
I'm happy to announce a new service by @FastRuby: Ruby on Rails Security Audits!
Read more about this over here: https://www.linkedin.com/pulse/new-service-ruby-rails-security-audits-fastrubyio-ernesto-tagwerker
-
I hope you can join us on Monday June 12th at 12pm ET! 📅
I know many would benefit from the content discussed in this session, and we look forward to answering all your questions.
SAVE YOUR SPOT over here 👉🏼 https://ombulabs.zoom.us/webinar/register/8016857349319/WN_8iJA29KBQjqfZEXqkKRnxA#/registration
-
Hi folks! I’m hosting a joint webinar with my friend @mbuckbee of Expedited Security and Wafris. We are going to talk about how you can secure your #RubyOnRails application. 🚀
Some topics I know will be of interest to the Rails Community… 🧵
-
@wj @p8 ohh yeah, that part is clear, @postmodern. I meant the part of #Rails 6.0.x branch with no patches for those CVEs, then warning in GitHub + different interpretation on what is patched at GitHub advisories & #rubysec - the latter is correct, IMO.
-
@wj @p8 ITOH #rubysec reports both, CVE-2023-22792 & CVE-2023-22795 affect all #rails versions, and there's no fix for 6.0.x branch
https://rubysec.com/advisories/CVE-2023-22792/
https://rubysec.com/advisories/CVE-2023-22795/Perhaps @postmodern can help here.
Nevertheless, I'd suggest an upgrade to rails 6.0.6.1 because CVE-2023-22794
https://rubysec.com/advisories/CVE-2023-22794/
Which is fixed by activerecord 6.0.6.1