bk99.de entertain the web since 1997

A Rails commit demonstrates unsafe mass assignment

Summary

Egor Homakov exploits a Rails mass assignment hole to push someone else's code into the public Rails repository. The vulnerability affected GitHub's Rails application. GitHub initially suspended Homakov.

Ideas

  • Mass assignment transfers unfiltered parameters directly to model attributes.
  • Insufficiently protected keys allow changes to ownership.
  • One platform bug can endanger the permissions of numerous projects.
  • A visible demonstration commit forced quick attention.

Insights

  • Framework convenience can hide security decisions.
  • Responsible disclosure needs reporting channels that are reachable and taken seriously.
  • Authorisation must check every state change independently of input validation.

Recommendations

  • Only allow explicitly named attributes to be changed.
  • Test authorisation with manipulated ownership and role fields.

References

Read the original article

Search the Web Archive