Dochie koodu ọjọọ n'ime ngwugwu Ruby Strong_password achọpụtara

В bipụtara Mwepụta June 25 nke ngwugwu gem Strong_password 0.7 kpughere mgbanwe obi ọjọọ (CVE-2019-13354), nbudata na ime koodu mpụga nke onye mwakpo amaghị ama na-achịkwa, na-akwado na ọrụ Pastebin. Ngụkọta ọnụ ọgụgụ nke nbudata nke oru ngo bụ 247 puku, na ụdị 0.6 bụ banyere 38 puku. Maka ụdị ọjọọ ahụ, a na-edepụta ọnụọgụ nbudata dị ka 537, mana o doro anya na nke a bụ eziokwu, ebe ọ bụ na ewepụrụlarị ntọhapụ a na Ruby Gems.

Ọbá akwụkwọ Strong_password na-enye ngwaọrụ maka ịlele ike nke paswọọdụ onye ọrụ akọwapụtara n'oge ndebanye aha.
N'etiti iji ngwugwu Strong_password think_feel_do_engine (nbudata puku iri isii na ise), chere_feel_do_dashboard (nbudata puku iri na ise) na
superhosting (1.5 puku). Achọpụtara na mgbanwe ọjọọ ahụ gbakwunyere onye amaghi ama weghaara njikwa nke ebe nchekwa ahụ n'aka onye edemede.

Agbakwunyere koodu ọjọọ ahụ naanị na RubyGems.org, Git ebe nchekwa emetụtaghị ọrụ ahụ. Achọpụtara nsogbu ahụ mgbe otu n'ime ndị mmepe, onye na-eji Strong_password na ọrụ ya, malitere ịchọpụta ihe mere e ji gbakwunye mgbanwe ikpeazụ na ebe nchekwa ihe karịrị ọnwa 6 gara aga, mana ntọhapụ ọhụrụ pụtara na RubyGems, nke e bipụtara n'aha ọhụrụ. maintainer, onye ọ dịghị onye nụrụ banyere ya tupu m anụghị ihe ọ bụla.

Onye mwakpo ahụ nwere ike mebie koodu aka ike na sava site na iji ụdị nsogbu Strong_password. Mgbe achọpụtara nsogbu na Pastebin, a na-ejuru edemede iji mee koodu ọ bụla onye ahịa gafere site na kuki "__id" wee tinye ya site na iji usoro Base64. Koodu ọjọọ ahụ zipụkwara paramita nke onye ọbịa nke arụnyere ụdị Strong_password ọjọọ na sava nke onye mwakpo na-achịkwa.

Dochie koodu ọjọọ n'ime ngwugwu Ruby Strong_password achọpụtara

Dochie koodu ọjọọ n'ime ngwugwu Ruby Strong_password achọpụtara

isi: opennet.ru

Tinye a comment