Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS13cnJ3LWNycDgtOTc5cc4AAuzs
Pageflow vulnerable to sensitive user data extraction via Ransack query injection
Impact
The attack allows extracting sensitive properties of database objects that are associated with users or entries belonging to an account that the attacker has access to.
Pageflow uses the ActiveAdmin
Ruby library to provide some management features to its users. ActiveAdmin
relies on the Ransack
library to implement search functionality. In its default configuration, Ransack
will allow for query conditions based on properties of associated database objects [1]. The *_starts_with
, *_ends_with
or *_contains
search matchers [2] can then be abused to exfiltrate sensitive string values of associated database objects via character-by-character brute-force.
[1] https://activerecord-hackery.github.io/ransack/going-further/associations/
[2] https://activerecord-hackery.github.io/ransack/getting-started/search-matches/
Mitigation
Upgrade to version 15.7.1 or 14.5.2 of the pageflow
gem.
For more information
If you have any questions or comments about this advisory email us at info(at)codevise.de
Credits Permalink: https://github.com/advisories/GHSA-wrrw-crp8-979q
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13cnJ3LWNycDgtOTc5cc4AAuzs
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 2 years ago
Updated: almost 2 years ago
Identifiers: GHSA-wrrw-crp8-979q
References:
- https://github.com/codevise/pageflow/security/advisories/GHSA-wrrw-crp8-979q
- https://github.com/codevise/pageflow/pull/1862
- https://github.com/advisories/GHSA-wrrw-crp8-979q
Blast Radius: 0.0
Affected Packages
rubygems:pageflow
Dependent packages: 27Dependent repositories: 39
Downloads: 205,379 total
Affected Version Ranges: >= 15.0.0, < 15.7.1, < 14.5.2
Fixed in: 15.7.1, 14.5.2
All affected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.1.0, 0.2.0, 0.2.1, 0.3.0, 0.4.0, 0.5.0, 0.6.0, 0.7.0, 0.7.1, 0.7.2, 0.8.0, 0.8.1, 0.8.2, 0.9.0, 0.9.1, 0.9.2, 0.10.0, 0.11.0, 0.11.1, 0.11.2, 0.11.3, 0.11.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 12.4.1, 12.5.0, 12.6.0, 13.0.0, 13.1.0, 13.2.0, 13.3.0, 13.4.0, 13.5.0, 13.6.0, 14.0.0, 14.1.0, 14.1.1, 14.2.0, 14.2.1, 14.3.0, 14.4.0, 14.5.0, 14.5.1, 15.0.0, 15.0.1, 15.0.2, 15.1.0, 15.1.1, 15.1.2, 15.2.0, 15.2.1, 15.2.2, 15.3.0, 15.4.0, 15.5.0, 15.6.0, 15.6.1, 15.7.0
All unaffected versions: 14.5.2, 15.7.1, 15.8.0, 16.0.0, 16.1.0, 16.2.0, 17.0.0, 17.0.1, 17.0.2, 17.0.3, 17.0.4