A Rails commit demonstrates unsafe mass assignment
Summary
Egor Homakov exploits a Rails mass assignment hole to push someone else's code into the public Rails repository. The vulnerability affected GitHub's Rails application. GitHub initially suspended Homakov.
Ideas
- Mass assignment transfers unfiltered parameters directly to model attributes.
- Insufficiently protected keys allow changes to ownership.
- One platform bug can endanger the permissions of numerous projects.
- A visible demonstration commit forced quick attention.
Insights
- Framework convenience can hide security decisions.
- Responsible disclosure needs reporting channels that are reachable and taken seriously.
- Authorisation must check every state change independently of input validation.
Recommendations
- Only allow explicitly named attributes to be changed.
- Test authorisation with manipulated ownership and role fields.
References
Links to the original source and the Web Archive open in a new tab.