Rails XML Parsing Vulnerability affecting JRuby users
groups.google.com
groups.google.com
* [CVE-2013-1855] XSS vulnerability in sanitize_css in Action Pack [1]
* [CVE-2013-1856] XML Parsing Vulnerability affecting JRuby users [2]
* [CVE-2013-1857] XSS Vulnerability in the `sanitize` helper of Ruby on Rails [3]
Two of these affect all Rails versions, not just JRuby, so are more serious.
[1] https://groups.google.com/forum/?fromgroups=#!topic/rubyonra...
[2] https://groups.google.com/forum/?fromgroups=#!topic/rubyonra...
[3] https://groups.google.com/forum/?fromgroups=#!topic/rubyonra...
Here is the fourth one:
https://groups.google.com/forum/#!topic/ruby-security-ann/o0...
The sole change seems to be in the regex that was used to match the protocol separator (i.e. the colon). The change is from this:
/:|(�*58)|(p)|(%|%)3A/
to this: /:|(�*58)|(p)|(�*3a)|(%|%)3A/i
Presumably the previous regex allowed an attacker to insert a variation of "javascript:foo()" and get past a HTML sanitize call.IMO, Rails has done a better job of this recently, and that makes me really happy.