{"id":103981,"date":"2022-05-09T09:36:45","date_gmt":"2022-05-09T07:36:45","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety"},"modified":"2022-05-09T09:36:45","modified_gmt":"2022-05-09T07:36:45","slug":"uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety","title":{"rendered":"Vulnerabilit\u00e0 in RubyGems.org che consente la sostituzione di pacchetti altrui","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00c8 stata identificata una vulnerabilit\u00e0 critica nel repository dei pacchetti RubyGems.org (CVE-2022-29176), che consente di sostituire alcuni pacchetti di terze parti nel repository senza le dovute autorizzazioni, avviando il ritiro (yank) di un pacchetto legittimo e caricando al suo posto un altro file con lo stesso nome e numero di versione.      <\/p>\n<p>Per sfruttare con successo la vulnerabilit\u00e0, sono necessarie tre condizioni:  <\/p>\n<ul>\n<li class=\"l\"> L'attacco pu\u00f2 essere effettuato solo su pacchetti il cui nome contiene il carattere trattino.\n<li class=\"l\"> L'attaccante deve poter pubblicare un pacchetto gem con una parte del nome fino al simbolo del trattino. Ad esempio, se l'attacco viene eseguito sul pacchetto \u00abrails-html-sanitizer\u00bb, l'attaccante deve pubblicare nel repository il proprio pacchetto \u00abrails-html\u00bb.\n<li class=\"l\"> Il pacchetto sotto attacco deve essere stato creato negli ultimi 30 giorni o non deve essere stato aggiornato negli ultimi 100 giorni.  <\/ul>\n<p>La vulnerabilit\u00e0 \u00e8 causata da un errore nel gestore dell'azione \u00abyank\u00bb, che interpreta la parte del nome dopo il trattino come il nome della piattaforma, permettendo di avviare la rimozione di pacchetti di terzi che corrispondono alla parte del nome fino al simbolo del trattino. In particolare, nel codice del gestore dell'operazione \u00abyank\u00bb per cercare i pacchetti veniva utilizzata la chiamata \u2018find_by!(full_name: \u00ab#{rubygem.name}-#{slug}\u00bb)\u2019, mentre il parametro \u00abslug\u00bb veniva passato dal proprietario del pacchetto per determinare la versione da rimuovere. Il proprietario del pacchetto \u00abrails-html\u00bb poteva invece specificare \u00absanitizer-1.2.3\u00bb invece della versione \u00ab1.2.3\u00bb, il che avrebbe comportato l'applicazione dell'operazione al pacchetto di terzi \u00abrails-html-sanitizer-1.2.3\u00bb.      <\/p>\n<p>Il problema \u00e8 stato identificato da un ricercatore di sicurezza nell'ambito di un programma attivo su HackerOne per il pagamento di ricompense per la scoperta di problemi di sicurezza in noti progetti open source. Il problema \u00e8 stato risolto in RubyGems.org il 5 maggio e, secondo quanto dichiarato dagli sviluppatori, non hanno finora trovato tracce di sfruttamento della vulnerabilit\u00e0 nei log degli ultimi 18 mesi. Tuttavia, \u00e8 stata effettuata solo una revisione superficiale, e in futuro \u00e8 previsto un controllo pi\u00f9 approfondito.     <\/p>\n<p>Per verificare i propri progetti \u00e8 consigliabile analizzare la cronologia delle operazioni nel file Gemfile.lock; l'attivit\u00e0 malevola si esprime nella presenza di modifiche mantenendo nome e versione o cambiando piattaforma (ad esempio, quando il pacchetto gemname-1.2.3 \u00e8 stato aggiornato a gemname-1.2.3-java). Come metodo di protezione contro la sostituzione nascosta dei pacchetti nei sistemi di integrazione continua o nella pubblicazione dei progetti, si consiglia agli sviluppatori di utilizzare Bundler con le opzioni \u00ab--frozen\u00bb o \u00ab--deployment\u00bb per fissare le dipendenze.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=57155\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 RubyGems.org \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-29176), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0431\u0435\u0437 \u043d\u0430\u043b\u0438\u0447\u0438\u044f \u0434\u043e\u043b\u0436\u043d\u044b\u0445 \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u0439 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0447\u0443\u0436\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0443\u0442\u0451\u043c \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u0437\u044a\u044f\u0442\u0438\u044f (yank) \u043b\u0435\u0433\u0438\u0442\u0438\u043c\u043d\u043e\u0433\u043e \u043f\u0430\u043a\u0435\u0442\u0430 \u0438 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0432\u043c\u0435\u0441\u0442\u043e \u043d\u0435\u0433\u043e \u0434\u0440\u0443\u0433\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430 \u0441 \u0442\u0435\u043c \u0436\u0435 \u0438\u043c\u0435\u043d\u0435\u043c \u0438 \u043d\u043e\u043c\u0435\u0440\u043e\u043c \u0432\u0435\u0440\u0441\u0438\u0438. \u0414\u043b\u044f \u0443\u0441\u043f\u0435\u0448\u043d\u043e\u0439 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0442\u0440\u0451\u0445 \u0443\u0441\u043b\u043e\u0432\u0438\u0439: \u0410\u0442\u0430\u043a\u0430 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0430 \u0442\u043e\u043b\u044c\u043a\u043e \u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u044b, \u0432 \u0438\u043c\u0435\u043d\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103981","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 RubyGems.org \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-29176), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0431\u0435\u0437 \u043d\u0430\u043b\u0438\u0447\u0438\u044f \u0434\u043e\u043b\u0436\u043d\u044b\u0445 \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u0439 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0447\u0443\u0436\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0443\u0442\u0451\u043c \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u0437\u044a\u044f\u0442\u0438\u044f (yank).\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 RubyGems.org, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u0447\u0443\u0436\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u044b | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 RubyGems.org \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-29176), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0431\u0435\u0437 \u043d\u0430\u043b\u0438\u0447\u0438\u044f \u0434\u043e\u043b\u0436\u043d\u044b\u0445 \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u0439 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0447\u0443\u0436\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0443\u0442\u0451\u043c \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u0437\u044a\u044f\u0442\u0438\u044f (yank).\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-05-09T07:36:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-05-09T07:36:45+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilit\u00e0 in RubyGems.org che consente la sostituzione di pacchetti di terzi | ProHoster","description":"\u00c8 stata scoperta una vulnerabilit\u00e0 critica nel repository di RubyGems.org (CVE-2022-29176) che consente di sostituire alcuni pacchetti altrui nel repository senza le necessarie autorizzazioni, avviando un ritiro (yank).","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 RubyGems.org, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u0447\u0443\u0436\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u044b | ProHoster","og:description":"\u0412 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 RubyGems.org \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-29176), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0431\u0435\u0437 \u043d\u0430\u043b\u0438\u0447\u0438\u044f \u0434\u043e\u043b\u0436\u043d\u044b\u0445 \u043f\u043e\u043b\u043d\u043e\u043c\u043e\u0447\u0438\u0439 \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0447\u0443\u0436\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u043f\u0443\u0442\u0451\u043c \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u0437\u044a\u044f\u0442\u0438\u044f (yank).","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-v-rubygems-org-pozvolyayushhaya-podmenit-chuzhie-pakety","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-05-09T07:36:45+00:00","article:modified_time":"2022-05-09T07:36:45+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103981","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-25 10:54:13","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-05-09 07:37:51","updated":"2026-01-25 10:54:13","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103981","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=103981"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/103981\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=103981"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=103981"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=103981"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}