ActionController::Base.param_parsers.delete(Mime::XML)
if i just stick it at the bottom of environment.rb, will that work? i am not sure how to test to confirm that i've fixed it.
ActionController::Base.param_parsers.delete(Mime::XML)
if i just stick it at the bottom of environment.rb, will that work? i am not sure how to test to confirm that i've fixed it.
curl -i -H "Content-Type: application/xml" -X POST -d '<id type="yaml">--- !ruby/object:ActionController::Base bar: 1</id>' http://localhost:3000
If in your logs the params[:id] is an object, then you are vulnerable. If it's just a string, then your fix worked.I put mine in an intializers file.
ActiveSupport::CoreExtensions::Hash::Conversions::XML_PARSING.delete('symbol')
ActiveSupport::CoreExtensions::Hash::Conversions::XML_PARSING.delete('yaml')EDIT AGAIN: I think putting it at the end of environment.rb works. I somehow messed it up and got confused, but then I tried it again and it worked. Just make sure you confirm your fix with the curl command!
Parameters: {"action"=>"list", "id"=>#<ActionController::Base:0x6dc4177ed940 @bar=1>, "controller"=>"news"}
Good would look something like this:
Parameters: {"action"=>"index", "id"=>"--- !ruby/object:ActionController::BaseIt's been like 4 years since i did this and haven't touched rails since.
What else do i need to do here to fix this? i Thought rails 3.2.11 was ok..
Hash::DisallowedType (Disallowed type attribute: "yaml"):
activesupport (3.2.11) lib/active_support/core_ext/hash/conversions.rb:112:in `typecast_xml_value'ActionController::Base.param_parsers.delete(Mime::XML)
This will disable parsing of xml which most people never use anyway
Parameters: {"id"=>#<ActionController::Base:0xb570d2e8 @bar=1>}
Why do you think I'm still unprotected after updating to the fixed version 2.3.15 referenced here? http://weblog.rubyonrails.org/2013/1/8/Rails-3-2-11-3-1-10-3...Or is there something I'm missing?
Disallowed type attribute: "yaml" curl -i -H "Content-Type: application/xml" -X POST -d '<id type="yaml">--- !ruby/object:ActionController::Base bar: 1</id>' --insecure https:localhost1. Edit Gemfile and change rails version from 2.3.14 to 2.3.15.
2. Commit and push changes
3. bundle exec cap deploy (this is our standard method and works well.)
4. Double check rails -v returns 2.3.15 on production server.
5. On the production server run
curl -i -H "Content-Type: application/xml" -X POST -d '<id type="yaml">--- !ruby/object:ActionController::Base bar: 1</id>' --insecure http://localhost
Result: Parameters: {"id"=>#<ActionController::Base:0xb570d2e8 @bar=1>}
Once I got the curl command to run against my production site (see my comment just below) and saw that it was still vulnerable, I quickly hacked ActionController::Base.param_parsers.delete(Mime::XML)
into environments.rb and re-deployed and that fixed it. Now when I run the curl command I get a parameter-less GET request in the log. I still do not understand why updating to 2.3.15 per the recommended method did not fix the problem, but at least our app doesn't need the xml in that way. "If you mean that your Ruby on Rails version is 1.2.6 then, no the vulnerability does not affect you as the feature was introduced in Ruby on Rails 2.0"
source: http://weblog.rubyonrails.org/2013/1/8/Rails-3-2-11-3-1-10-3...Thanks for the help!
Edit: fixed using above info from vinhboy. thanks heaps :)