Ruby on Rails(3.2.9, 3.1.8, 3.0.17以å)ã®find_by_*ã¡ã½ããã«SQLã¤ã³ã¸ã§ã¯ã·ã§ã³èå¼±æ§ãè¦ã¤ããã¾ãã(CVE-2012-5664)ããã®ã¨ã³ããªã§ã¯ãã®æ¦è¦ã¨å¯¾çã«ã¤ãã¦èª¬æãã¾ãã æ¦è¦ Ruby on Railsã®find_by_*ã¡ã½ããã®å¼æ°ã¨ãã¦ããã·ã¥ãæå®ãããã¨ã§ãä»»æã®SELECTæãå®è¡ã§ããèå¼±æ§ãããã¾ãã æ¤è¨¼ Ruby on Rails3.2.9ã®ç°å¢ãç¨æãã¦ã以ä¸ã®2ã¤ã®ã¢ãã«ãç¨æãã¾ããã $ rails g scaffold user name:string email:string $ rails g scaffold book author:string title:string ã¢ãã«Userã¯å人æ å ±ãä¿æãã¦ãããèªåèªèº«ã®æ å ±ã®ã¿ãé²è¦§ã§ããã¨ããæ³å®ã§ããã¢ãã«Bookã¯æ¸èªãã¼ã¿ãã¼ã¹ã§ã
Rails Brakemanã¯Railsã¢ããªã±ã¼ã·ã§ã³ã®ãªãã¸ããªãèªã¿è¾¼ãã§ã»ãã¥ãªãã£ãã§ãã¯ãã¦ããããµã¼ãã¹ã§ãã ã»ãã¥ã¢ãªããã°ã©ãã³ã°ãããããã®ãã¦ãã¦ã¯å¹¾ã¤ãããã¾ããã¤ã¾ãããã«æ²¿ã£ã¦ç¾ç¶ã®ã³ã¼ãã確èªããã°ãä¸ä¸ã®ã»ãã¥ãªãã£ã¤ã³ã·ãã³ããæªç¶ã«é²ããããç¥ãã¾ãããRailsã¢ããªã±ã¼ã·ã§ã³ã«ã¤ãã¦ãããè¡ãã®ãRails Brakemanã§ãã ããã¸ã§ã¯ã詳細ããããã£ã¦ä¸è¦§ã§ç¢ºèªã§ãã¾ãã ã»ãã¥ãªãã£ã¦ã©ã¼ãã³ã°ãã¢ãã«ããã¥ã¼ã®ã»ãã¥ãªãã£ã¦ã©ã¼ãã³ã°ãåºã¦ãã¾ãã ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°é¢ä¿ã®ã¦ã©ã¼ãã³ã°ãå¤ãã§ãã ã¯ãªãã¯ããã¨ã©ã®è¡ã«ãããè¦åã確èªã§ãã¾ãã Rails Brakemanã§ã¯ç²ç®çã«ãã©ã¡ã¼ã¿ãæ¾ãè¾¼ãã ãããã®çµæããã®ã¾ã¾ãªãã¤ã¬ã¯ãã«ä½¿ã£ãããããã¨ãç¦ãã¦ãã¾ãããªããã®ãã§ãã¯ã¯ãã°ãçºè¦ãã¦ãã訳ã§ã¯ãªããã»ã
Github ã«èå¼±æ§ããã£ã人㯠Rails ã«æããã¡ãªèå¼±æ§ã issue ã«æãã¦ãããç¸æã«ããããå®éã«ãããçªãã¦ãããä¸è¦ childish ã ããããã ãç°¡åã«èå¼±ãªå®è£ ããªããã¦ãã¾ãã¨ãããã¨ã ãé±æãã®ä»æ¥ãRubyist ã¯ã¾ãé¢é£æ å ±ã«ä¸èªãã â Yuki Nishijima (@yuki24) March 4, 2012 æ°ã«ãªã£ã¦èª¿ã¹ãã®ã§ã¡ã¢ãèªåãæ°ãã¤ããªãã¨ãªã¼ã Public Key Security Vulnerability and Mitigation - github.com/blog/ github ã«èå¼±æ§ããã£ã¦ãããçªããããããã Rails ã¢ããªã«ãããã¡ãªèå¼±æ§ã®ä¸ã¤ãMass assignment ã¨ãããã¿ã¤ãã®èå¼±æ§ã§ããã mass assignment èå¼±æ§ã¨ã¯ mass assignment èå¼±æ§ã¨ã¯ä½ãã
ãã®ã¦ã§ããµã¤ãã¯è²©å£²ç¨ã§ãï¼ monoweb.info ã¯ãããªãããæ¢ãã®æ å ±ã®å ¨ã¦ã®ææ°ãã¤æé©ãªã½ã¼ã¹ã§ããä¸è¬ãããã¯ããããããæ¤ç´¢ã§ããå 容ã¯ãmonoweb.infoãå ¨ã¦ã¨ãªãã¾ããããªãããæ¢ãã®å 容ãè¦ã¤ãããã¨ãé¡ã£ã¦ãã¾ãï¼
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}