home.social

#rubysec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rubysec, aggregated by home.social.

fetched live
  1. 💣 Is your #Ruby app vulnerable to known CVEs? Is it safe in production? Is it ready for a #SOC2 audit?

    If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!

    go.fastruby.io/wbw

    #RubySec #InfoSec #DevSecOps

  2. PSA: supply chain attacks (aka forking popular gems, changing the name slightly, and adding malicious code) are starting to show up on rubygems.org more often. Be cautious when adding a new gem to your project. Check who the author is, check the GitHub repository, look at the commit history, etc.
    socket.dev/blog/malicious-ruby

    #ruby #security #rubysec

  3. PSA: supply chain attacks (aka forking popular gems, changing the name slightly, and adding malicious code) are starting to show up on rubygems.org more often. Be cautious when adding a new gem to your project. Check who the author is, check the GitHub repository, look at the commit history, etc.
    socket.dev/blog/malicious-ruby

    #ruby #security #rubysec

  4. 💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it safe in production?

    If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!

    go.fastruby.io/wbw

    #RubySec #InfoSec #DevSecOps

  5. Heads Up Everyone. An unpatched CVE for Sinatra was just added to ruby-advisory-db. Currently all versions are affected. Impact is a possible Open Redirect.
    github.com/advisories/GHSA-hxx
    #ruby #sinatra #rubysec

  6. Heads Up Everyone. An unpatched CVE for Sinatra was just added to ruby-advisory-db. Currently all versions are affected. Impact is a possible Open Redirect.
    github.com/advisories/GHSA-hxx
    #ruby #sinatra #rubysec

  7. Heads Up Everyone: there's an not-yet-patched-and-released security vulnerability in WEBrick. This is going to be added to ruby-advisory-db shortly, so don't be surprised if webrick starts getting flagged; although I'm guessing it's probably only in your Gemfile.lock due to some other gem pulling it in.

    Update: webrick 1.8.2 has now been released.

    github.com/advisories/GHSA-6f6

    #ruby #rubysec #webrick

  8. Heads Up Everyone: there's an not-yet-patched-and-released security vulnerability in WEBrick. This is going to be added to ruby-advisory-db shortly, so don't be surprised if webrick starts getting flagged; although I'm guessing it's probably only in your Gemfile.lock due to some other gem pulling it in.

    Update: webrick 1.8.2 has now been released.

    github.com/advisories/GHSA-6f6

    #ruby #rubysec #webrick

  9. Thank you to @havenwood for updating the ruby-versions repo for CVE-2024-27282! ruby-install users, please upgrade your ruby versions!

    ruby-install --update
    ruby-install ruby-3.0.7
    ruby-install ruby-3.1.5
    ruby-install ruby-3.2.4
    ruby-install ruby-3.3.1

    ruby-lang.org/en/news/2024/04/
    #ruby #rubysec #cve #cve_2024_2782 #cve20242782

  10. Thank you to @havenwood for updating the ruby-versions repo for CVE-2024-27282! ruby-install users, please upgrade your ruby versions!

    ruby-install --update
    ruby-install ruby-3.0.7
    ruby-install ruby-3.1.5
    ruby-install ruby-3.2.4
    ruby-install ruby-3.3.1

    ruby-lang.org/en/news/2024/04/
    #ruby #rubysec #cve #cve_2024_2782 #cve20242782

  11. PyPI temporarily halted new user signups in response to a surge in malicious typosquating packages. I suspect attackers will turn their sights to NPM and rubygems.org next.
    arstechnica.com/security/2024/
    #rubygems #rubysec

  12. PyPI temporarily halted new user signups in response to a surge in malicious typosquating packages. I suspect attackers will turn their sights to NPM and rubygems.org next.
    arstechnica.com/security/2024/
    #rubygems #rubysec

  13. 💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it safe in production?

    go.fastruby.io/wbw

    #RubySec #InfoSec #DevSecOps

  14. 💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it safe in production?

    If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!

    go.fastruby.io/wbw

    #RubySec #InfoSec #DevSecOps

  15. 💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it safe in production?

    If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!

    go.fastruby.io/hqh

    #RubySec #InfoSec #DevSecOps

  16. 💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it safe in production?

    If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!

    go.fastruby.io/hqh

    #RubySec #InfoSec #DevSecOps

  17. 💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it secure enough?

    If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!

    fastruby.io/security-audit?utm

    #RubySec #InfoSec #DevSecOps

  18. 💣 Is your #Ruby app vulnerable? Is it a ticking time bomb or is it secure enough?

    If you don’t know, you need a security audit. Find out how many vulnerabilities are present in your code and dependencies. Let's talk!

    fastruby.io/security-audit?utm

    #RubySec #InfoSec #DevSecOps

  19. So it appears that the jquery-ui-rails gem is abandoned? Are there any plans to find a new maintainer, or ping the author? The gem is currently vulnerable to multiple old XSSs from jQuery 1.30.0.
    github.com/jquery-ui-rails/jqu
    nvd.nist.gov/vuln/detail/CVE-2

    /cc @joliss
    #rails #jqueryui #rubysec

  20. If you know anyone who might be interested in this type of audits, feel free to share it with them. Thank you! 🚀 #RubySec #RailsSec #InfoSec

  21. I hope you can join us on Monday June 12th at 12pm ET! 📅

    I know many would benefit from the content discussed in this session, and we look forward to answering all your questions.

    SAVE YOUR SPOT over here 👉🏼 ombulabs.zoom.us/webinar/regis

    #Webinar #Security #CISO #Rails #RubySec

  22. Hi folks! I’m hosting a joint webinar with my friend @mbuckbee of Expedited Security and Wafris. We are going to talk about how you can secure your #RubyOnRails application. 🚀

    Some topics I know will be of interest to the Rails Community… 🧵

    #Infosec #CISO #RubySec

  23. @wj @p8 ohh yeah, that part is clear, @postmodern. I meant the part of #Rails 6.0.x branch with no patches for those CVEs, then warning in GitHub + different interpretation on what is patched at GitHub advisories & #rubysec - the latter is correct, IMO.

  24. @wj @p8 ITOH #rubysec reports both, CVE-2023-22792 & CVE-2023-22795 affect all #rails versions, and there's no fix for 6.0.x branch

    rubysec.com/advisories/CVE-202
    rubysec.com/advisories/CVE-202

    Perhaps @postmodern can help here.

    Nevertheless, I'd suggest an upgrade to rails 6.0.6.1 because CVE-2023-22794

    rubysec.com/advisories/CVE-202

    Which is fixed by activerecord 6.0.6.1

    my.diffend.io/gems/activerecor