Kutsiviwa kwekodhi yakaipa muRuby package Strong_password yaonekwa

Π’ rakabudiswa June 25 kuburitswa kwegem package Yakasimba_password 0.7 pachena kuchinja kwakashata (CVE-2019-13354), kudhawunirodha nekuita kodhi yekunze inodzorwa neanorwisa asingazivikanwe, anogarwa paPastebin sevhisi. Nhamba yose yekurodha yeprojekiti ndeye 247 zviuru, uye shanduro 0.6 inenge 38 zviuru. Kune iyo yakaipa vhezheni, nhamba yekurodha yakanyorwa se537, asi hazvisi pachena kuti izvi ndezvechokwadi sei, zvichipihwa kuti kuburitswa uku kwakatobviswa kubva kuRuby Gems.

Iyo Strong_password raibhurari inopa zvishandiso zvekutarisa kusimba kwepassword inotsanangurwa nemushandisi panguva yekunyoresa.
Pakati pe uchishandisa iyo Strong_password mapakeji think_feel_do_engine (65 zviuru zvekudhawunirodha), think_feel_do_dashboard (15 zviuru zvekurodha) uye
superhosting (1.5 zviuru). Zvinocherechedzwa kuti shanduko yakaipa yakawedzerwa nemunhu asingazivikanwe akabata kutonga repository kubva kumunyori.

Iyo yakaipa kodhi yakawedzerwa kuRubyGems.org chete, Git repository purojekiti haina kukanganiswa. Dambudziko rakaonekwa mushure mekunge mumwe wevagadziri, anoshandisa Strong_password mumapurojekiti ake, akatanga kufunga kuti sei shanduko yekupedzisira yakawedzerwa kune repository kupfuura mwedzi mitanhatu yapfuura, asi kuburitswa kutsva kwakaonekwa paRubyGems, yakabudiswa pachinzvimbo chetsva. muchengeti, uyo akanga asina kumbonzwa nezvake ndisati ndanzwa chinhu.

Munhu anorwisa anogona kuburitsa bumbiro remutemo pamaseva achishandisa dambudziko reStrong_password. Pakaonekwa dambudziko nePastebin, script yakatakurwa kuti imhanye chero kodhi yakapfuura nemutengi kuburikidza neCookie "__id" uye yakavharirwa uchishandisa nzira yeBase64. Kodhi ine hutsinye yakatumirawo maparamendi emugamuchiri pakaiswa iyo yakaipa Strong_password musiyano kune server inodzorwa neanorwisa.

Kutsiviwa kwekodhi yakaipa muRuby package Strong_password yaonekwa

Kutsiviwa kwekodhi yakaipa muRuby package Strong_password yaonekwa

Source: opennet.ru

Voeg