Remote command execution In savon
Description
Savon::Model evaluates WSDL operation names as Ruby source
Impact
Savon::Model generated SOAP operation methods by interpolating operation names into Ruby source passed to module_eval. An attacker who can control the operation names of a WSDL, can inject Ruby code that executes in the application process. This affects only the .all_operations class method provided by Savon::Model to automatically register all operations provided by the WSDL. Configuring Savon::Model with trusted operation names via .operations is safe.
Patches
Patched in Savon 2.17.2.
Users should upgrade to 2.17.2 or later.
Workarounds
Avoid .all_operations for untrusted WSDL documents. Use .operations with trusted operation names instead.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rubygems | 2.17.2 |
Aliases
References