Project

General

Profile

Actions

Bug #20271

closed

Safe mode rendering does not correctly prevent using symbol to proc calls

Added by Tomer Brisker almost 7 years ago. Updated almost 6 years ago.

Status:
Closed
Priority:
High
Assignee:
Category:
Security
Target version:

Description

Using methods such as `.each`, a user can pass as an argument a symbol to be called, for example `.each(&:delete)`.
This allows execution of commands that should be blocked by the jail.
A fix proposal in the safemode gem has been suggested: https://github.com/svenfuchs/safemode/pull/23
Once it is merged we should update our version of the gem to the latest one.


Related issues 1 (0 open1 closed)

Copied to Katello - Bug #20836: Safe mode rendering does not correctly prevent using symbol to proc callsClosedMarek Hulán07/11/2017Actions
Actions

Also available in: Atom PDF