Remote Code Execution in CouchDB (and Privilege Escalation in the Npm Registry)
justi.cz
justi.cz
https://blog.couchdb.org/2017/11/14/apache-couchdb-cve-2017-...
I really appreciated the quick response of the CouchDB team and how they handled rolling out the patch.
> jsx:decode(<<"{\"foo\":\"bar\", \"foo\":\"baz\"}">>, [return_maps]).
#{<<"foo">> => <<"baz">>}
The actual problem seems to me the difference in the model (list of items, which "works" for duplicate keys, vs. maps).http://seriot.ch/parsing_json.php
It's not just JSON by the way. URL parsers also differ in how they handle malformed inputs, with potentially catastrophic results:
https://www.blackhat.com/docs/us-17/thursday/us-17-Tsai-A-Ne...
Basically the entire web stack is made up of protocols that are weakly specified, open to interpretation, lacking reference implementations and are therefore very hack prone.
I'm not saying what javascript does is smart, or the right way, or anything like that, but JSON is defined specifically as "a subset of Javascript", as such I find it normal to expect that javascript rules applies.
Of course, one could argue that a key being defined twice is undefined behavior (is it ? I admit to not reading the javascript specs) and thus "what the js implementations actually do" isn't a reference.
https://www.ietf.org/rfc/rfc4627.txt says "The names within an object SHOULD be unique". https://tools.ietf.org/html/rfc7159 is more lax and instead says "An object whose names are all unique is interoperable in the sense that all software implementations receiving that object will agree on the name-value mappings". It's unfortunate that the correct behavior is not agreed on and today we saw the consequences of that.