Brightbox
  • Home
  • Pricing & Sign up
  • Why Brightbox?
  • Products & Services
  • FAQs
  • About
  • Blog
  • Wiki
  • Contact
Blog RSS feed
POSTED BY

George Hills

george@brightbox.co.uk

twitter_banner

Recent Posts

  • Ubuntu 12.04 LTS “Precise” now available
  • Ubuntu 12.04 LTS "Precise" beta testing
  • Another Rails JSON security bug
  • Rails JSON and XML security bugs
  • Rails SQL injection vulnerability

Another Rails JSON security bug 30 Jan 13

Another serious vulnerability in Rails has been discovered. Similarly to the last one, it concerns the parsing of JSON request bodies and can result in an attacker bypassing code, such as authentication systems, and may also be used to run arbitrary Ruby code and even execute system commands.

This new vulnerability does not affect Rails 3.1 and 3.2. Applications using Rails 3.0 and Rails 2.3 are vulnerable. We do not have any details about releases prior to 2.3, but these should be assumed to be vulnerable as well.

The rubyonrails.org blog post has more details of this newly-discovered vulnerability – CVE-2013-0333. Rails 2.3 and 3.0 apps need upgrading (or the workaround implemented) to fix the new JSON vulnerabilites.

Please note that this issues is separate to the SQL injection vulnerability and XML+JSON vulnerabilities. Even if you have already taken action against these earlier bugs, further work is now needed to protect against this new one.

We urge all customers to upgrade as soon as possible.

Posted 30 January 2013 by George Hills


Recent blog posts

  • Ubuntu 12.04 LTS “Precise” now available
    about 1 month ago
  • Ubuntu 12.04 LTS “Precise” beta testing
    2 months ago
  • Another Rails JSON security bug
    4 months ago
  • Rails JSON and XML security bugs
    5 months ago
  • Rails SQL injection vulnerability
    5 months ago
  • New Relic Agent vulnerability
    6 months ago

Join our email list

Flickr (more...)

RSS feeds

Blog feed

Flickr feed

Recent Wiki updates

System Status feed




Wiki | Forums | Terms & Conditions | Privacy | Site Map

Copyright © 2011 Brightbox Systems Ltd. All rights reserved