HomeSecurityRails Apps Vulnerability Allows Remote Code Execution

Rails Apps vulnerability allows remote code execution

Researchers have discovered a critical security vulnerability in Rails Apps that leverages the Bootsnap caching library . This exploit allows attackers to achieve remote code execution ( RCE ) by exploiting an arbitrary file write vulnerability.

See also: HPE Aruba network vulnerabilities allow arbitrary code execution

Rails Apps vulnerability remote code execution

The issue is particularly concerning as Bootsnap has been a default component in Rails since version 5.2.

According to the Conviso research team, in this scenario, users can control both the file path and the content. This allows malicious actors to write files to arbitrary locations on the server, potentially leading to RCE.

Despite the exploit's capabilities, some limitations make it difficult to execute. Rails production environments often use Docker containers with restricted writable directories such as /tmp, db , and log. However, these limitations can be circumvented by targeting specific writable directories, such as tmp/cache/bootsnap.

Bootsnap optimizes Rails Apps by caching precise calculations. cache files are stored in tmp/cache/bootsnap and contain compiled Ruby files. These files follow a specific structure consisting of a header (cache key) and the compiled content.

See also: Fortinet: Vulnerability used to install remote access software

Rails Apps vulnerability allows remote code execution
Vulnerability in Rails Apps allows RCE

By replacing a cache file with malicious Ruby code and triggering its execution at startup , attackers can achieve RCE. An overview of the exploitation process is as follows:

  • Identify Target File: Selects a file that is likely to be executed when the application starts (e.g. set.rb from the Ruby standard library).
  • Generate Malicious Cache: Generates a cache key using Bootsnap's hashing mechanism. Embeds malicious Ruby code into the cache file.
  • Write Malicious Cache: Exploits the arbitrary file write vulnerability to overwrite the target cache file.
  • Restart Application: Triggers a server restart by writing to tmp/restart.txt, leveraging Puma's restart feature.
  • Execute Malicious Code: Upon restart, the application loads the malicious cache file, executing the attacker's payload.

See also: Fortinet vulnerabilities allow hackers to execute code remotely

Remote Code Execution (RCE) is a dangerous threat to computer system security. It is a vulnerability in which a malicious user can execute code on a remote computer or server without authorization, as in the case of Rails Apps. Typically, attackers exploit security vulnerabilities in software or applications to gain access, which can lead to dangerous situations, such as data theft, system corruption, or even complete control of the targeted device. It is critical that security mechanisms are regularly updated to prevent these attacks.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS