{"id":103981,"date":"2022-05-09T09:36:45","date_gmt":"2022-05-09T07:36:45","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety"},"modified":"2022-05-09T09:36:45","modified_gmt":"2022-05-09T07:36:45","slug":"uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety","title":{"rendered":"Vulnerabilit\u00e0 in RubyGems.org che consente di sostituire pacchetti di altri","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nel repository di pacchetti RubyGems.org \u00e8 stata identificata una vulnerabilit\u00e0 critica (CVE-2022-29176), che consente, in assenza dei necessari permessi, di sostituire alcuni pacchetti altrui nel repository mediante l'inizio di un'operazione di rimozione (yank) di un pacchetto legittimo e il caricamento al suo posto di un altro file con lo stesso nome e numero di versione.      <\/p>\n<p>Per sfruttare con successo la vulnerabilit\u00e0 \u00e8 necessario che siano soddisfatte tre condizioni:  <\/p>\n<ul>\n<li class=\"l\"> L'attacco pu\u00f2 essere effettuato solo su pacchetti il cui nome contiene il carattere trattino.\n<li class=\"l\"> L'attaccante deve essere in grado di posizionare un pacchetto gem con parte del nome fino al carattere trattino. Ad esempio, se l'attacco viene effettuato sul pacchetto \u00abrails-html-sanitizer\u00bb, l'attaccante deve posizionare nel repository il proprio pacchetto \u00abrails-html\u00bb.\n<li class=\"l\"> Il pacchetto bersaglio dell'attacco deve essere stato creato negli ultimi 30 giorni o non essere stato aggiornato negli ultimi 100 giorni.  <\/ul>\n<p>La vulnerabilit\u00e0 \u00e8 causata da un errore nel gestore dell'azione \u00abyank\u00bb, che interpreta la parte del nome dopo il trattino come il nome della piattaforma, permettendo di avviare la rimozione di pacchetti altrui che corrispondono nella parte del nome fino al trattino. In particolare, nel codice del gestore dell'operazione \u00abyank\u00bb, per cercare i pacchetti \u00e8 stata utilizzata la chiamata \u2018find_by!(full_name: \u00ab#{rubygem.name}-#{slug}\u00bb)\u2019, dove il parametro \u00abslug\u00bb veniva fornito dal proprietario del pacchetto per identificare la versione da rimuovere. Il proprietario del pacchetto \u00abrails-html\u00bb poteva invece indicare \u00absanitizer-1.2.3\u00bb invece della versione \u00ab1.2.3\u00bb, il che porterebbe ad applicare l'operazione a un pacchetto altrui \u00abrails-html-sanitizer-1.2.3\u00bb.      <\/p>\n<p>Il problema \u00e8 stato identificato da un ricercatore di sicurezza nell'ambito del programma attivo su HackerOne di ricompense per la segnalazione di problemi di sicurezza in noti progetti open source. La questione \u00e8 stata risolta in RubyGems.org il 5 maggio e, secondo quanto dichiarato dagli sviluppatori, al momento non sono state trovate tracce di sfruttamento della vulnerabilit\u00e0 nei log degli ultimi 18 mesi. Finora \u00e8 stata condotta solo una revisione superficiale e si prevede di effettuare un controllo pi\u00f9 approfondito in seguito.     <\/p>\n<p>Si raccomanda di analizzare la cronologia delle operazioni nel file Gemfile.lock per verificare i propri progetti, l'attivit\u00e0 dannosa si manifesta con modifiche mantenendo il nome e la versione o cambiando la piattaforma (ad esempio, quando il pacchetto gemname-1.2.3 \u00e8 stato aggiornato a gemname-1.2.3-java). Come metodo alternativo per proteggersi dalla sostituzione nascosta dei pacchetti nei sistemi di integrazione continua o durante la pubblicazione dei progetti, \u00e8 consigliato agli sviluppatori di utilizzare Bundler con le opzioni \u00ab--frozen\u00bb o \u00ab--deployment\u00bb per fissare le dipendenze.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=57155\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 RubyGems.org \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-29176), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0431\u0435\u0437 \u043d\u0430\u043b\u0438\u0447\u0438\u044f \u0434\u043e\u043b\u0436\u043d\u044b\u0445 \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u0439 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0447\u0443\u0436\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0443\u0442\u0451\u043c \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u0437\u044a\u044f\u0442\u0438\u044f (yank) \u043b\u0435\u0433\u0438\u0442\u0438\u043c\u043d\u043e\u0433\u043e \u043f\u0430\u043a\u0435\u0442\u0430 \u0438 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0432\u043c\u0435\u0441\u0442\u043e \u043d\u0435\u0433\u043e \u0434\u0440\u0443\u0433\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430 \u0441 \u0442\u0435\u043c \u0436\u0435 \u0438\u043c\u0435\u043d\u0435\u043c \u0438 \u043d\u043e\u043c\u0435\u0440\u043e\u043c \u0432\u0435\u0440\u0441\u0438\u0438. \u0414\u043b\u044f \u0443\u0441\u043f\u0435\u0448\u043d\u043e\u0439 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0442\u0440\u0451\u0445 \u0443\u0441\u043b\u043e\u0432\u0438\u0439: \u0410\u0442\u0430\u043a\u0430 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0430 \u0442\u043e\u043b\u044c\u043a\u043e \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b, \u0432 \u0438\u043c\u0435\u043d\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103981","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 RubyGems.org \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-29176), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0431\u0435\u0437 \u043d\u0430\u043b\u0438\u0447\u0438\u044f \u0434\u043e\u043b\u0436\u043d\u044b\u0445 \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u0439 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0447\u0443\u0436\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0443\u0442\u0451\u043c \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u0437\u044a\u044f\u0442\u0438\u044f (yank).\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 RubyGems.org, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u0447\u0443\u0436\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u044b | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 RubyGems.org \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-29176), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0431\u0435\u0437 \u043d\u0430\u043b\u0438\u0447\u0438\u044f \u0434\u043e\u043b\u0436\u043d\u044b\u0445 \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u0439 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0447\u0443\u0436\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0443\u0442\u0451\u043c \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u0437\u044a\u044f\u0442\u0438\u044f (yank).\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-05-09T07:36:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-05-09T07:36:45+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 in RubyGems.org che consente di sostituire pacchetti di terzi | ProHoster","description":"Nel repository di RubyGems.org \u00e8 stata identificata una vulnerabilit\u00e0 critica (CVE-2022-29176) che consente, senza le dovute autorizzazioni, di sostituire alcuni pacchetti di terzi nel repository tramite l'inizio di un'estrazione (yank).","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 RubyGems.org, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u0447\u0443\u0436\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u044b | ProHoster","og:description":"\u0412 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 RubyGems.org \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-29176), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0431\u0435\u0437 \u043d\u0430\u043b\u0438\u0447\u0438\u044f \u0434\u043e\u043b\u0436\u043d\u044b\u0445 \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u0439 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0447\u0443\u0436\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0443\u0442\u0451\u043c \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u0437\u044a\u044f\u0442\u0438\u044f (yank).","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-05-09T07:36:45+00:00","article:modified_time":"2022-05-09T07:36:45+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103981","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-25 10:54:13","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-05-09 07:37:51","updated":"2026-01-25 10:54:13","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103981","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=103981"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103981\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=103981"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=103981"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=103981"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}