Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1301973 - (CVE-2016-0753) CVE-2016-0753 rubygem-activemodel, rubygem-activerecord: possible input validation circumvention in Active Model
CVE-2016-0753 rubygem-activemodel, rubygem-activerecord: possible input valid...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20160125,repor...
: Security
Depends On: 1301975 1301976 1301977 1301978 1301979 1306286 1306287 1306290 1306291
Blocks: 1302006
  Show dependency treegraph
 
Reported: 2016-01-26 08:15 EST by Adam Mariš
Modified: 2016-04-26 12:23 EDT (History)
56 users (show)

See Also:
Fixed In Version: rubygem-activemodel 5.0.0.beta1.1, rubygem-activemodel 4.2.5.1, rubygem-activemodel 4.1.14.1, rubygem-activerecord 5.0.0.beta1.1, rubygem-activerecord 4.2.5.1, rubygem-activerecord 4.1.14.1
Doc Type: Bug Fix
Doc Text:
A flaw was found in the way the Active Model based models processed attributes. An attacker with the ability to pass arbitrary attributes to models could possibly use this flaw to bypass input validation.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-02-24 05:58:32 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:0296 normal SHIPPED_LIVE Important: rh-ror41 security update 2016-02-24 10:36:00 EST

  None (edit)
Description Adam Mariš 2016-01-26 08:15:15 EST
A possible input validation circumvention vulnerability in Active Model was reported. Code that uses Active Model based models (including Active Record models) and does not validate user input before passing it to the model can be subject to an attack where specially crafted input will cause the model to skip validations.

External References:

https://groups.google.com/forum/#!msg/rubyonrails-security/6jQVC1geukQ/8oYETcxbFQAJ
http://weblog.rubyonrails.org/2016/1/25/Rails-5-0-0-beta1-1-4-2-5-1-4-1-14-1-3-2-22-1-and-rails-html-sanitizer-1-0-3-have-been-released/
Comment 4 Adam Mariš 2016-01-26 08:17:53 EST
Created rubygem-activerecord tracking bugs for this issue:

Affects: fedora-all [bug 1301979]
Comment 5 Adam Mariš 2016-01-26 08:18:12 EST
Created rubygem-activemodel tracking bugs for this issue:

Affects: fedora-all [bug 1301977]
Comment 6 Adam Mariš 2016-01-26 10:24:24 EST
Acknowledgments:

Red Hat would like to thank Ruby on Rails project for reporting this issue.
Upstream acknowledges John Backus from BlockScore as the original reporter.
Comment 8 Ján Rusnačko 2016-02-10 07:23:03 EST
Analysis:

Several class attributes, including validation related, of Active Model models were writable from instances. Attacker with ability to pass arbitrary attributes to Active Model instances could use this to bypass validation. Impacted code:

```ruby
SomeModel.new(unverified_user_input)
```

Mitigation:

Do not allow arbitrary attributes to be passed to models. In Rails with Strong Parameters, make sure to not call permit! method, which bypasses strong parameters protections. Outside of rails, use whitelisting to filter only allowed attributes before passing them to models.
Comment 11 errata-xmlrpc 2016-02-24 05:37:39 EST
This issue has been addressed in the following products:

  Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 7
  Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
  Red Hat Software Collections for Red Hat Enterprise Linux 6

Via RHSA-2016:0296 https://rhn.redhat.com/errata/RHSA-2016-0296.html
Comment 12 Fedora Update System 2016-02-28 03:23:53 EST
rubygem-activerecord-4.2.0-2.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
Comment 13 Fedora Update System 2016-02-28 03:25:19 EST
rubygem-actionpack-4.2.0-3.fc22, rubygem-activemodel-4.2.0-2.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
Comment 14 Fedora Update System 2016-02-28 03:28:29 EST
rubygem-activesupport-4.2.0-4.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
Comment 15 Fedora Update System 2016-02-28 07:24:05 EST
rubygem-activerecord-4.2.3-2.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
Comment 16 Fedora Update System 2016-02-28 07:25:17 EST
rubygem-activemodel-4.2.3-2.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.