Ukufakwa esikhundleni kwekhodi enonya kuphakheji ye-Ruby Strong_password kutholiwe

Π’ kushicilelwe Juni 25 ukukhishwa kwephakheji ye-gem Strong_password 0.7 kwembulwa ushintsho olubi (I-CVE-2019-13354), ukulanda nokusebenzisa ikhodi yangaphandle elawulwa umhlaseli ongaziwa, osingathwe kusevisi ye-Pastebin. Inani eliphelele lokulandwa kwephrojekthi liyizinkulungwane ezingama-247, kanti inguqulo 0.6 imayelana nezinkulungwane ezingama-38. Ngenguqulo enonya, inombolo yokulandwa ifakwe kuhlu njenge-537, kodwa akucaci ukuthi lokhu kunembe kangakanani, njengoba lokhu kukhishwa sekususiwe kakade ku-Ruby Gems.

Ilabhulali ye-Strong_password inikeza amathuluzi okuhlola amandla ephasiwedi eshiwo umsebenzisi ngesikhathi sokubhalisa.
Phakathi kwe usebenzisa amaphakheji we-Strong_password think_feel_do_engine (okulandwayo okuyizinkulungwane ezingu-65), think_feel_do_dashboard (ukulanda okuyizinkulungwane ezingu-15) kanye
ukusingathwa okuphezulu (izinkulungwane eziyi-1.5). Kuyaphawulwa ukuthi lolu shintsho olunonya lwengezwe ngumuntu ongaziwa obambe ukulawula kwenqolobane kumbhali.

Ikhodi enonya yengezwe kuphela ku-RubyGems.org, Inqolobane ye-Git iphrojekthi ayizange ithinteke. Inkinga ikhonjwe ngemuva kokuthi omunye wabathuthukisi, osebenzisa i-Strong_password kumaphrojekthi akhe, waqala ukuthola ukuthi kungani ushintsho lokugcina lwengezwe endaweni yokugcina izinyanga ezingaphezu kwe-6 edlule, kodwa ukukhululwa okusha kwavela ku-RubyGems, eshicilelwe egameni elisha. umnakekeli, okungekho muntu owayezwile ngaye ngaphambi kokuthi ngizwe lutho.

Umhlaseli angenza ikhodi engafanele kumaseva esebenzisa inguqulo eyinkinga ye-Strong_password. Lapho kutholwa inkinga nge-Pastebin, iskripthi salayishwa ukuze kusetshenziswe noma iyiphi ikhodi ephasiswe iklayenti nge-Cookie "__id" futhi yabhalwa ngekhodi kusetshenziswa indlela ye-Base64. Ikhodi enonya iphinde yathumela amapharamitha womsingathi lapho okuhlukile kwe-Strong_password eyingozi efakwe kuseva elawulwa umhlaseli.

Ukufakwa esikhundleni kwekhodi enonya kuphakheji ye-Ruby Strong_password kutholiwe

Ukufakwa esikhundleni kwekhodi enonya kuphakheji ye-Ruby Strong_password kutholiwe

Source: opennet.ru

Engeza amazwana