This project is archived and is in readonly mode.
XSS hole in String % (with Hash) on 1.8
-
Bruno Michel
There is only a very restrictive set of operations on string that return html_safe strings (IIRC,
<<,+andconcat). Other operations return unsafe strings by design. For example, in Rails 3.0.0:ruby-1.9.2-p0 > ("%s aa".html_safe % ['<script>x</script>']).html_safe? => false ruby-1.9.2-p0 > ("<a>%{x}</a>".html_safe % {:x=>'<script>y</script>'}).html_safe? => falseSo, there are no XSS holes, but if you want to preserve HTML markup from the original string, you have to do it yourself.
-
grosser
ahh % with array is not affected
ree-1.8.7-2010.01 > ("%s aa".html_safe % ['<script>x</script>']).html_safe? => falsebut % with hash is:
ree-1.8.7-2010.01 > ("<a>%{x}</a>".html_safe % {:x=>'<script>y</script>'}).html_safe? => trueso maybe its a 1.8 bug
-
grosser
- Title changed from html_safe is not honored by String#% to XSS hole in String % (with Hash) on 1.8
-
David Trasbo
- State changed from new to invalid
- Importance changed from to Low
I think this is a REE related issue. 1.8 doesn't even support the Hash syntax, and here's what happens on 1.9:
➜ irb ruby-1.9.2-p0 > require 'active_support/core_ext/string/output_safety' => true ruby-1.9.2-p0 > ("%{foo}".html_safe % {:foo => '<script></script>'}).html_safe? => falseMaybe REE's String#% manipulates
selfinstead of making a new String object? -
grosser
The i18n gem loaded by rails adds the % method supporting hash to string.
(This kind of replacement is often used when adding something into translations.)ree-1.8.7-2010.01 > "%{x}y" %{:x=>1} => "1y" -
David Trasbo
Which means this is not Rails' but i18n's fault.
-
grosser
I think rails should take care of all html_safe related methods, so they do not get spread out into multiple places.
My idea for a patch:
if ("%{x}".html_safe%{:x=>1}).html_safe? # fix hash replacement being safe on ruby 1.8 module HtmlSafePercent
def %(*args) String.new(super) end
end String.send(:include, HtmlSafePercent) end -
grosser
that should have been one block...
-
dncastilho (at gmail)
also affecting me on rails 3 + ruby 1.9.2 ... pretty annoying! does anyone have a patch suggestion for this?