Class: Brakeman::CheckRender

Inherits:
BaseCheck show all
Defined in:
lib/brakeman/checks/check_render.rb

Overview

Check calls to render() for dangerous values

Constant Summary

Constants inherited from BaseCheck

BaseCheck::CONFIDENCE

Constants included from Util

Util::ALL_PARAMETERS, Util::COOKIES, Util::COOKIES_SEXP, Util::PARAMETERS, Util::PARAMS_SEXP, Util::PATH_PARAMETERS, Util::QUERY_PARAMETERS, Util::REQUEST_ENV, Util::REQUEST_PARAMETERS, Util::REQUEST_PARAMS, Util::SESSION, Util::SESSION_SEXP

Constants inherited from SexpProcessor

SexpProcessor::VERSION

Instance Attribute Summary

Attributes inherited from BaseCheck

#tracker, #warnings

Attributes inherited from SexpProcessor

#context, #env, #expected

Instance Method Summary collapse

Methods inherited from BaseCheck

#add_result, inherited, #initialize, #process_call, #process_cookies, #process_default, #process_dstr, #process_if, #process_params

Methods included from Util

#array?, #block?, #call?, #camelize, #class_name, #constant?, #contains_class?, #context_for, #cookies?, #false?, #file_by_name, #file_for, #github_url, #hash?, #hash_access, #hash_insert, #hash_iterate, #integer?, #make_call, #node_type?, #number?, #params?, #pluralize, #rails_version, #regexp?, #relative_path, #request_env?, #request_value?, #result?, #set_env_defaults, #sexp?, #string?, #string_interp?, #symbol?, #table_to_csv, #template_path_to_name, #true?, #truncate_table, #underscore

Methods included from ProcessorHelper

#current_file_name, #process_all, #process_all!, #process_call_args, #process_call_defn?, #process_class, #process_module

Methods inherited from SexpProcessor

#in_context, #initialize, #process, processors, #scope

Constructor Details

This class inherits a constructor from Brakeman::BaseCheck

Instance Method Details

#check_for_dynamic_path(result) ⇒ Object

Check if path to action or file is determined dynamically



32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
# File 'lib/brakeman/checks/check_render.rb', line 32

def check_for_dynamic_path result
  view = result[:call][2]

  if sexp? view and original? result

    if input = has_immediate_user_input?(view)
      if string_interp? view
        confidence = CONFIDENCE[:med]
      else
        confidence = CONFIDENCE[:high]
      end
    elsif input = include_user_input?(view)
      confidence = CONFIDENCE[:low]
    else
      return
    end

    return if input.type == :model #skip models
    return if safe_param? input.match

    message = "Render path contains #{friendly_type_of input}"

    warn :result => result,
      :warning_type => "Dynamic Render Path",
      :warning_code => :dynamic_render_path,
      :message => message,
      :user_input => input,
      :confidence => confidence
  end
end

#check_for_rce(result) ⇒ Object



63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
# File 'lib/brakeman/checks/check_render.rb', line 63

def check_for_rce result
  return unless version_between? "0.0.0", "3.2.22" or
                version_between? "4.0.0", "4.1.14" or
                version_between? "4.2.0", "4.2.5"


  view = result[:call][2]
  if sexp? view and not duplicate? result
    if params? view
      add_result result
      return if safe_param? view

      warn :result => result,
        :warning_type => "Remote Code Execution",
        :warning_code => :dynamic_render_path_rce,
        :message => "Passing query parameters to render() is vulnerable in Rails #{rails_version} (CVE-2016-0752)",
        :user_input => view,
        :confidence => CONFIDENCE[:high]
    end
  end
end

#process_render_result(result) ⇒ Object



15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
# File 'lib/brakeman/checks/check_render.rb', line 15

def process_render_result result
  return unless node_type? result[:call], :render

  case result[:call].render_type
  when :partial, :template, :action, :file
    check_for_rce(result) or
      check_for_dynamic_path(result)
  when :inline
  when :js
  when :json
  when :text
  when :update
  when :xml
  end
end

#run_checkObject



9
10
11
12
13
# File 'lib/brakeman/checks/check_render.rb', line 9

def run_check
  tracker.find_call(:target => nil, :method => :render).each do |result|
    process_render_result result
  end
end

#safe_param?(exp) ⇒ Boolean

Returns:

  • (Boolean)


85
86
87
88
89
90
91
92
93
94
95
96
# File 'lib/brakeman/checks/check_render.rb', line 85

def safe_param? exp
  if params? exp and call? exp
    method_name = exp.method

    if method_name == :[]
      arg = exp.first_arg
      symbol? arg and [:controller, :action].include? arg.value
    else
      boolean_method? method_name
    end
  end
end