Researchers have discovered a critical security vulnerability in Rails Apps that leverages the Bootsnap caching library . This exploit allows attackers to achieve remote code execution ( RCE ) by exploiting an arbitrary file write vulnerability.
See also: HPE Aruba network vulnerabilities allow arbitrary code execution

The issue is particularly concerning as Bootsnap has been a default component in Rails since version 5.2.
According to the Conviso research team, in this scenario, users can control both the file path and the content. This allows malicious actors to write files to arbitrary locations on the server, potentially leading to RCE.
Despite the exploit's capabilities, some limitations make it difficult to execute. Rails production environments often use Docker containers with restricted writable directories such as /tmp, db , and log. However, these limitations can be circumvented by targeting specific writable directories, such as tmp/cache/bootsnap.
Bootsnap optimizes Rails Apps by caching precise calculations. cache files are stored in tmp/cache/bootsnap and contain compiled Ruby files. These files follow a specific structure consisting of a header (cache key) and the compiled content.
See also: Fortinet: Vulnerability used to install remote access software

By replacing a cache file with malicious Ruby code and triggering its execution at startup , attackers can achieve RCE. An overview of the exploitation process is as follows:
- Identify Target File: Selects a file that is likely to be executed when the application starts (e.g. set.rb from the Ruby standard library).
- Generate Malicious Cache: Generates a cache key using Bootsnap's hashing mechanism. Embeds malicious Ruby code into the cache file.
- Write Malicious Cache: Exploits the arbitrary file write vulnerability to overwrite the target cache file.
- Restart Application: Triggers a server restart by writing to tmp/restart.txt, leveraging Puma's restart feature.
- Execute Malicious Code: Upon restart, the application loads the malicious cache file, executing the attacker's payload.
See also: Fortinet vulnerabilities allow hackers to execute code remotely
Remote Code Execution (RCE) is a dangerous threat to computer system security. It is a vulnerability in which a malicious user can execute code on a remote computer or server without authorization, as in the case of Rails Apps. Typically, attackers exploit security vulnerabilities in software or applications to gain access, which can lead to dangerous situations, such as data theft, system corruption, or even complete control of the targeted device. It is critical that security mechanisms are regularly updated to prevent these attacks.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
