This project is closed and read-only.
Actions
Bug #811
closedDocumentation Patch: Preventing XPath Injection attacks
Bug #811:
Documentation Patch: Preventing XPath Injection attacks
Description
=begin
Here's a patch to rexml/xpath.rb which documents the variables parameter
in REXML::XPath. I have previously posted this as ruby-core:16626, but it was ignored.
Please apply it to ruby 1.8 and ruby 1.9, to encourage secure coding practices.
--- xpath.rb.old 2008-04-24 17:31:51.000000000 -0500
+++ xpath.rb 2008-04-24 17:37:38.000000000 -0500
@@ -15,10 +15,15 @@
# node matching '*'.
# namespaces::
# If supplied, a Hash which defines a namespace mapping.
-
def XPath::first element, path=nil, namespaces=nil, variables={}
raise "The namespaces argument, if supplied, must be a hash object." unless namespaces.nil? or namespaces.kind_of?(Hash)
raise "The variables argument, if supplied, must be a hash object." unless variables.kind_of?(Hash)
@@ -38,10 +43,16 @@
# The xpath to search for. If not supplied or nil, defaults to '*'
# namespaces::
# If supplied, a Hash which defines a namespace mapping -
# {|el| ... } def XPath::each element, path=nil, namespaces=nil, variables={}, &block raise "The namespaces argument, if supplied, must be a hash object." unless namespaces.nil? or namespaces.kind_of?(Hash) raise "The variables argument, if supplied, must be a hash object." unless variables.kind_of?(Hash)
=end
Updated by matz (Yukihiro Matsumoto) almost 18 years ago
- Status changed from Open to Closed
- % Done changed from 0 to 100
=begin
Applied in changeset r20455.
=end
Actions