[#92891] Question: ruby 2.7.0-preview1 also upgrades bundler to 2.1.0.pre.1? — Al Snow <jasnow@...>
Tried the new 2.7.0-preview1 upgrade to Ruby and see that bundler is also upgraded (to 2.1.0.pre.1).
5 messages
2019/05/30
[#92892] Re: Question: ruby 2.7.0-preview1 also upgrades bundler to 2.1.0.pre.1?
— SHIBATA Hiroshi <hsbt@...>
2019/05/30
Bundler 2.1.0.pree.1 is the expected version.
[ruby-core:92580] [Ruby trunk Bug#15835] Path traversal symlink - WEBrick
From:
mishra.dhiraj95@...
Date:
2019-05-07 09:33:18 UTC
List:
ruby-core #92580
Issue #15835 has been reported by Dhiraj (Dhiraj Mishra). ---------------------------------------- Bug #15835: Path traversal symlink - WEBrick https://bugs.ruby-lang.org/issues/15835 * Author: Dhiraj (Dhiraj Mishra) * Status: Open * Priority: Normal * Assignee: * Target version: * ruby -v: 2.6.3 * Backport: 2.4: UNKNOWN, 2.5: UNKNOWN, 2.6: UNKNOWN ---------------------------------------- **Summary:** A path traversal issue was observed in WEBrick ( WEBrick/1.4.2 (Ruby/2.6.3/2019-04-16)) via symlink. WEBrick serves static page for the current directory once enabled, however using symlink attacker could view data outside the hosted/running directory. **Steps to reproduce:** > mkdir nothing > cd nothing > ln -s ../../ symlnk > ruby -run -ehttpd . -p8080 **Impact:** This would allow the attacker to view sensitive data outside the root/running directory. **Recommendation:** We can probably educate users about this behavior in the WebBrick documentation and providing a flag/parameter to disable/enable following symlinks. -- https://bugs.ruby-lang.org/ Unsubscribe: <mailto:ruby-core-request@ruby-lang.org?subject=unsubscribe> <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-core>