From 741ead5e17886e2f16ebabb14f26331155eb8747 Mon Sep 17 00:00:00 2001 From: James Mason Date: Tue, 10 Oct 2017 10:18:05 -0700 Subject: [PATCH 1/4] Sanitize venue website link re: https://hakiri.io/github/openSUSE/osem/master/78eb58c93eb766505dd12319d0502c10b40a811f/warnings/342830caaa3c94 --- app/views/conferences/_venue.html.haml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/views/conferences/_venue.html.haml b/app/views/conferences/_venue.html.haml index 62af90c7..5aee70af 100644 --- a/app/views/conferences/_venue.html.haml +++ b/app/views/conferences/_venue.html.haml @@ -32,4 +32,4 @@ = @conference.venue.country_name - if @conference.venue.website %br - =link_to @conference.venue.website, @conference.venue.website + = sanitize link_to(@conference.venue.website, @conference.venue.website) From 9b5a6ddb5c1ad00c83c68f65aedacf97c5dc34d7 Mon Sep 17 00:00:00 2001 From: James Mason Date: Tue, 10 Oct 2017 10:22:49 -0700 Subject: [PATCH 2/4] Sanitize conference color to prevent CSS XSS injection re: https://hakiri.io/github/openSUSE/osem/master/78eb58c93eb766505dd12319d0502c10b40a811f/warnings/7138485d39fea3 --- app/views/conferences/show.html.haml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/views/conferences/show.html.haml b/app/views/conferences/show.html.haml index f94b8ee4..5022a7a1 100644 --- a/app/views/conferences/show.html.haml +++ b/app/views/conferences/show.html.haml @@ -82,7 +82,7 @@ - content_for :script_head do :javascript - var triangle_tcs = tinycolor("#{@conference.color}").monochromatic(); + var triangle_tcs = tinycolor("#{sanitize @conference.color}").monochromatic(); var triangle_colors = triangle_tcs.map(function(t) { return t.toHexString(); }); $(function () { $(document).ready(function() { From c48f458a8097919196dc72df73f6f0a1dd3080b4 Mon Sep 17 00:00:00 2001 From: James Mason Date: Tue, 10 Oct 2017 10:25:49 -0700 Subject: [PATCH 3/4] Sanitize venue location attributes to prevent XSS JS injection re: https://hakiri.io/github/openSUSE/osem/master/78eb58c93eb766505dd12319d0502c10b40a811f/warnings/77d3a6b478a6ae https://hakiri.io/github/openSUSE/osem/master/78eb58c93eb766505dd12319d0502c10b40a811f/warnings/dae7946eda6b58 https://hakiri.io/github/openSUSE/osem/master/78eb58c93eb766505dd12319d0502c10b40a811f/warnings/466b2dce554973 --- app/views/conferences/_venue_map.html.haml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/app/views/conferences/_venue_map.html.haml b/app/views/conferences/_venue_map.html.haml index b58b3053..b4326924 100644 --- a/app/views/conferences/_venue_map.html.haml +++ b/app/views/conferences/_venue_map.html.haml @@ -3,14 +3,14 @@ - content_for(:script_body) do :javascript // create a map in the "map" div, set the view to a given place and zoom - var map = L.map('map', { scrollWheelZoom: false }).setView([#{@conference.venue.latitude}, #{@conference.venue.longitude}], 11); + var map = L.map('map', { scrollWheelZoom: false }).setView([#{sanitize @conference.venue.latitude}, #{sanitize @conference.venue.longitude}], 11); // add an OpenStreetMap tile layer L.tileLayer('//{s}.tile.openstreetmap.org/{z}/{x}/{y}.png', { attribution: 'Map data © OpenStreetMap contributors, CC-BY-SA, Imagery © Mapbox', maxZoom: 18 }).addTo(map); // add a marker in the given location, attach some popup content to it and open the popup - L.marker([#{@conference.venue.latitude}, #{@conference.venue.longitude}]).addTo(map) + L.marker([#{sanitize @conference.venue.latitude}, #{sanitize @conference.venue.longitude}]).addTo(map) .bindPopup("#{popup}") .openPopup(); // Turn scrollwheel on when user clicks From d5d9ca16e05c531d6b7d0a8c93816bceb0302845 Mon Sep 17 00:00:00 2001 From: James Mason Date: Tue, 10 Oct 2017 10:34:16 -0700 Subject: [PATCH 4/4] Require a version of nokogiri with known vulnerabilities resolved re: https://hakiri.io/github/openSUSE/osem/master/78eb58c93eb766505dd12319d0502c10b40a811f/warnings/b532fbd10b687d --- Gemfile | 5 +++++ Gemfile.lock | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/Gemfile b/Gemfile index 7f25aa46..22dc5f6e 100644 --- a/Gemfile +++ b/Gemfile @@ -200,6 +200,11 @@ gem 'sprockets-rails' # for multiple speakers select on proposal/event forms gem 'selectize-rails' +# Nokogiri < 1.8.1 is subject to: +# CVE-2017-0663, CVE-2017-7375, CVE-2017-7376, CVE-2017-9047, CVE-2017-9048, +# CVE-2017-9049, CVE-2017-9050 +gem 'nokogiri', '>= 1.8.1' + # Use guard and spring for testing in development group :development do # to launch specs when files are modified diff --git a/Gemfile.lock b/Gemfile.lock index c6b4faa8..c140ffdf 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -290,7 +290,7 @@ GEM mysql2 (0.4.9) nenv (0.3.0) netrc (0.11.0) - nokogiri (1.8.0) + nokogiri (1.8.1) mini_portile2 (~> 2.2.0) notiffany (0.1.1) nenv (~> 0.1)