Rails XSS vulnerability in number formatting (CVE-2014-0081)
groups.google.com
groups.google.com
You have to be using number_to_currency (common), but also passing in user input to the parameters format, negative_format or units which would not be a good idea anyway and is unlikely to have been done. I can't think why you would do that without verifying the unit and matching against a small set of acceptable currency units.
You'd have to be doing this:
<%= number_to_currency(number, format: unknown_user_text) %>Hopefully no Bitcoin apps use the currency helper. But I imagine in the context of an exchange the numbers come from the blockchain or a wallet, and aren't user controlled in the way that could be exploited.
https://github.com/search?q=number_to_currency+in%3Afile+lan...
https://github.com/search?q=number_to_human+in%3Afile+langua...
https://github.com/search?q=number_to_percentage+in%3Afile+l...
Disclaimer: not a RoR developer.
I can't look at the diff for some reason (too many redirects), but I'd guess this issue was the result of some logic that was implemented before SafeBuffers were added.
PHP's number_format() doesn't escape for HTML - is that an XSS bug too?
Here's the version for use in a view context: https://github.com/rails/rails/blob/master/actionview/lib/ac...
You can see that this method has some XSS prevention logic.
Here's the converter itself: https://github.com/rails/rails/blob/master/activesupport/lib...
We are seeing web development moving to other platforms - true. Part of this is down to a change in the typical requirements for a web app. Some of it is probably down to performance, although in most cases Rails performs well enough with an engineer who knows what they're doing. Almost none of that shift is down to security issues, of which there are few.
Rails is a good, probably the best, general purpose web framework, and no-one claims otherwise.