This project is archived and is in readonly mode.
request.remote_ip/X-Forwarded-For may not be an IP
-
Michael Koziarski
- Milestone set to 3.0.5
- Importance changed from to Low
The attack vectors they're talking about there assume no one does any sanitization. SQL Injection, shell script exploits etc only apply if people don't check those inputs.
There's certainly a bug here, but it's not a security bug.
-
Michael Koziarski
- Title changed from rails security bug - request.remote_ip/X-Forwarded-For not sanitized to request.remote_ip/X-Forwarded-For may not be an IP
-
Christopher Meiklejohn
Is the issue here just that the input isn't validated as an actual IP address?
-
alindeman
I'd be happy to help fix this, but there are a existing few tests that make me wonder what the expected behavior is:
request = stub_request 'HTTP_X_FORWARDED_FOR' => 'unknown,192.168.0.1' assert_equal 'unknown', request.remote_ipAs the tests are written, it seems like returning a string (non-IP) was thought about. What's the expected behavior here then?