Validate gem name before building compact index cache paths#9717
Open
hsbt wants to merge 1 commit into
Open
Conversation
Bundler::CompactIndexClient::Cache#info_path and #info_etag_path join the gem name into the cache directory without validation. The name comes from the remote index, either versions lines or transitive dependency names in info files, so a crafted name like "../../../../pwn" escapes the cache directory because the special-characters branch keeps the raw name and only appends an MD5 suffix. Reject any name that is not a plain basename before constructing the path, matching the fetch_spec guard from 56ed326, and apply the same guard to the independent Gem::CompactIndexClient::Cache port. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bundler::CompactIndexClient::Cachebuilds info cache paths by joining the gem name into the cache directory. The name comes from the remote index, either versions lines or transitive dependency names in info files, and is never validated, so a name like../../../../pwnescapes the cache directory because the special-characters branch keeps the raw name and only appends an MD5 suffix.info_etag_pathembeds the raw name the same way. This rejects any name that is not a plain basename before constructing the path, matching thefetch_specguard from 56ed326, and applies the same guard to the independentGem::CompactIndexClient::Cacheport. Existing cache files keep their names, so no cache is invalidated.