2019-12-08 14:19:20 +01:00
[
2021-04-04 17:10:08 +02:00
{
"id" : 175966226 ,
"name" : "CVE-2019-5418" ,
"full_name" : "mpgn\/CVE-2019-5418" ,
"owner" : {
"login" : "mpgn" ,
"id" : 5891788 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/5891788?v=4" ,
"html_url" : "https:\/\/github.com\/mpgn"
} ,
"html_url" : "https:\/\/github.com\/mpgn\/CVE-2019-5418" ,
"description" : "CVE-2019-5418 - File Content Disclosure on Ruby on Rails" ,
"fork" : false ,
"created_at" : "2019-03-16T11:58:18Z" ,
2023-09-28 14:53:01 +02:00
"updated_at" : "2023-09-28T10:59:28Z" ,
2021-04-06 05:11:05 +02:00
"pushed_at" : "2021-04-05T21:28:36Z" ,
2023-09-28 14:53:01 +02:00
"stargazers_count" : 192 ,
"watchers_count" : 192 ,
2022-11-08 07:19:29 +01:00
"has_discussions" : false ,
2023-05-25 02:28:33 +02:00
"forks_count" : 24 ,
2021-09-13 23:12:57 +02:00
"allow_forking" : true ,
2021-10-06 23:13:51 +02:00
"is_template" : false ,
2022-06-28 20:20:29 +02:00
"web_commit_signoff_required" : false ,
2021-10-06 23:13:51 +02:00
"topics" : [
"rails"
] ,
2021-10-01 23:13:10 +02:00
"visibility" : "public" ,
2023-05-25 02:28:33 +02:00
"forks" : 24 ,
2023-09-28 14:53:01 +02:00
"watchers" : 192 ,
2023-06-19 15:46:37 +02:00
"score" : 0 ,
2023-06-22 02:26:12 +02:00
"subscribers_count" : 4
2021-04-04 17:10:08 +02:00
} ,
2022-08-05 02:16:53 +02:00
{
"id" : 176323109 ,
"name" : "CVE-2019-5418" ,
"full_name" : "omarkurt\/CVE-2019-5418" ,
"owner" : {
"login" : "omarkurt" ,
"id" : 1712468 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/1712468?v=4" ,
"html_url" : "https:\/\/github.com\/omarkurt"
} ,
"html_url" : "https:\/\/github.com\/omarkurt\/CVE-2019-5418" ,
"description" : "File Content Disclosure on Rails Test Case - CVE-2019-5418" ,
"fork" : false ,
"created_at" : "2019-03-18T16:09:13Z" ,
"updated_at" : "2021-06-23T14:36:20Z" ,
"pushed_at" : "2019-03-18T16:15:25Z" ,
"stargazers_count" : 5 ,
"watchers_count" : 5 ,
2022-11-08 07:19:29 +01:00
"has_discussions" : false ,
2023-06-12 20:30:51 +02:00
"forks_count" : 2 ,
2022-08-05 02:16:53 +02:00
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [
"cve-2019-5418" ,
"ror" ,
"vulnerable-app"
] ,
"visibility" : "public" ,
2023-06-12 20:30:51 +02:00
"forks" : 2 ,
2022-08-05 02:16:53 +02:00
"watchers" : 5 ,
2023-06-19 15:46:37 +02:00
"score" : 0 ,
"subscribers_count" : 0
2022-08-05 02:16:53 +02:00
} ,
{
"id" : 176545257 ,
"name" : "CVE-2019-5418-Scanner" ,
"full_name" : "brompwnie\/CVE-2019-5418-Scanner" ,
"owner" : {
"login" : "brompwnie" ,
"id" : 8638589 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/8638589?v=4" ,
"html_url" : "https:\/\/github.com\/brompwnie"
} ,
"html_url" : "https:\/\/github.com\/brompwnie\/CVE-2019-5418-Scanner" ,
"description" : "A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418" ,
"fork" : false ,
"created_at" : "2019-03-19T15:38:01Z" ,
2023-09-28 14:53:01 +02:00
"updated_at" : "2023-09-28T10:59:36Z" ,
2022-08-05 02:16:53 +02:00
"pushed_at" : "2019-03-21T17:26:06Z" ,
2023-09-28 14:53:01 +02:00
"stargazers_count" : 35 ,
"watchers_count" : 35 ,
2022-11-08 07:19:29 +01:00
"has_discussions" : false ,
2022-08-05 02:16:53 +02:00
"forks_count" : 16 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 16 ,
2023-09-28 14:53:01 +02:00
"watchers" : 35 ,
2023-06-19 15:46:37 +02:00
"score" : 0 ,
2023-07-03 02:29:41 +02:00
"subscribers_count" : 3
2022-08-05 02:16:53 +02:00
} ,
2019-12-08 14:19:20 +01:00
{
2019-12-12 06:14:27 +01:00
"id" : 177236589 ,
"name" : "Rails-doubletap-RCE" ,
"full_name" : "mpgn\/Rails-doubletap-RCE" ,
2019-12-12 05:48:20 +01:00
"owner" : {
2019-12-12 06:14:27 +01:00
"login" : "mpgn" ,
"id" : 5891788 ,
2021-01-21 16:10:20 +01:00
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/5891788?v=4" ,
2019-12-12 06:14:27 +01:00
"html_url" : "https:\/\/github.com\/mpgn"
2019-12-12 05:48:20 +01:00
} ,
2019-12-12 06:14:27 +01:00
"html_url" : "https:\/\/github.com\/mpgn\/Rails-doubletap-RCE" ,
"description" : "RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)" ,
2019-12-12 05:48:20 +01:00
"fork" : false ,
2019-12-12 06:14:27 +01:00
"created_at" : "2019-03-23T02:52:31Z" ,
2023-12-08 13:42:34 +01:00
"updated_at" : "2023-12-08T09:20:13Z" ,
2023-01-19 13:33:38 +01:00
"pushed_at" : "2023-01-19T12:13:40Z" ,
2023-12-08 13:42:34 +01:00
"stargazers_count" : 128 ,
"watchers_count" : 128 ,
2022-11-08 07:19:29 +01:00
"has_discussions" : false ,
2023-12-11 19:44:54 +01:00
"forks_count" : 33 ,
2021-09-13 23:12:57 +02:00
"allow_forking" : true ,
2021-10-06 23:13:51 +02:00
"is_template" : false ,
2022-06-28 20:20:29 +02:00
"web_commit_signoff_required" : false ,
2021-10-06 23:13:51 +02:00
"topics" : [
"rails"
] ,
2021-10-01 23:13:10 +02:00
"visibility" : "public" ,
2023-12-11 19:44:54 +01:00
"forks" : 33 ,
2023-12-08 13:42:34 +01:00
"watchers" : 128 ,
2023-06-19 15:46:37 +02:00
"score" : 0 ,
2023-06-22 02:26:12 +02:00
"subscribers_count" : 7
2022-08-05 02:16:53 +02:00
} ,
{
"id" : 178527770 ,
"name" : "CVE-2019-5418" ,
"full_name" : "takeokunn\/CVE-2019-5418" ,
"owner" : {
"login" : "takeokunn" ,
"id" : 11222510 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/11222510?v=4" ,
"html_url" : "https:\/\/github.com\/takeokunn"
} ,
"html_url" : "https:\/\/github.com\/takeokunn\/CVE-2019-5418" ,
"description" : null ,
"fork" : false ,
"created_at" : "2019-03-30T07:40:11Z" ,
"updated_at" : "2019-10-24T19:07:56Z" ,
"pushed_at" : "2019-03-30T07:54:58Z" ,
"stargazers_count" : 2 ,
"watchers_count" : 2 ,
2022-11-08 07:19:29 +01:00
"has_discussions" : false ,
2022-08-05 02:16:53 +02:00
"forks_count" : 2 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 2 ,
"watchers" : 2 ,
2023-06-19 15:46:37 +02:00
"score" : 0 ,
"subscribers_count" : 2
2022-08-05 02:16:53 +02:00
} ,
{
"id" : 178909066 ,
"name" : "RailroadBandit" ,
"full_name" : "Bad3r\/RailroadBandit" ,
"owner" : {
"login" : "Bad3r" ,
"id" : 25513724 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/25513724?v=4" ,
"html_url" : "https:\/\/github.com\/Bad3r"
} ,
"html_url" : "https:\/\/github.com\/Bad3r\/RailroadBandit" ,
"description" : "a demo for Ruby on Rails CVE-2019-5418" ,
"fork" : false ,
"created_at" : "2019-04-01T17:02:57Z" ,
2023-04-12 14:36:16 +02:00
"updated_at" : "2023-04-12T09:49:39Z" ,
2022-08-05 02:16:53 +02:00
"pushed_at" : "2019-04-11T22:45:52Z" ,
2023-04-12 14:36:16 +02:00
"stargazers_count" : 2 ,
"watchers_count" : 2 ,
2022-11-08 07:19:29 +01:00
"has_discussions" : false ,
2022-08-05 02:16:53 +02:00
"forks_count" : 0 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 0 ,
2023-04-12 14:36:16 +02:00
"watchers" : 2 ,
2023-06-19 15:46:37 +02:00
"score" : 0 ,
"subscribers_count" : 1
2022-08-05 02:16:53 +02:00
} ,
2022-10-17 14:17:39 +02:00
{
2023-01-02 13:13:52 +01:00
"id" : 212888337 ,
"name" : "CVE-2019-5418-Rails3" ,
"full_name" : "ztgrace\/CVE-2019-5418-Rails3" ,
"owner" : {
"login" : "ztgrace" ,
"id" : 2554037 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/2554037?v=4" ,
"html_url" : "https:\/\/github.com\/ztgrace"
} ,
"html_url" : "https:\/\/github.com\/ztgrace\/CVE-2019-5418-Rails3" ,
"description" : "Rails 3 PoC of CVE-2019-5418" ,
"fork" : false ,
"created_at" : "2019-10-04T19:28:10Z" ,
"updated_at" : "2019-10-04T19:29:56Z" ,
2023-07-14 02:28:00 +02:00
"pushed_at" : "2023-07-13T22:14:58Z" ,
2023-01-02 13:13:52 +01:00
"stargazers_count" : 0 ,
"watchers_count" : 0 ,
"has_discussions" : false ,
"forks_count" : 1 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 1 ,
"watchers" : 0 ,
2023-06-19 15:46:37 +02:00
"score" : 0 ,
"subscribers_count" : 2
2023-01-02 13:13:52 +01:00
} ,
{
"id" : 222660643 ,
2022-10-17 14:17:39 +02:00
"name" : "CVE-2019-5418" ,
2023-01-02 13:13:52 +01:00
"full_name" : "random-robbie\/CVE-2019-5418" ,
2022-10-17 14:17:39 +02:00
"owner" : {
2023-01-02 13:13:52 +01:00
"login" : "random-robbie" ,
"id" : 4902869 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/4902869?v=4" ,
"html_url" : "https:\/\/github.com\/random-robbie"
2022-10-17 14:17:39 +02:00
} ,
2023-01-02 13:13:52 +01:00
"html_url" : "https:\/\/github.com\/random-robbie\/CVE-2019-5418" ,
"description" : null ,
2022-10-17 14:17:39 +02:00
"fork" : false ,
2023-01-02 13:13:52 +01:00
"created_at" : "2019-11-19T09:40:06Z" ,
"updated_at" : "2021-04-26T19:41:51Z" ,
"pushed_at" : "2019-11-19T09:41:18Z" ,
"stargazers_count" : 5 ,
"watchers_count" : 5 ,
2022-11-08 07:19:29 +01:00
"has_discussions" : false ,
2023-01-02 13:13:52 +01:00
"forks_count" : 1 ,
2022-10-17 14:17:39 +02:00
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
2023-01-02 13:13:52 +01:00
"forks" : 1 ,
"watchers" : 5 ,
2023-06-19 15:46:37 +02:00
"score" : 0 ,
2023-06-25 02:26:29 +02:00
"subscribers_count" : 3
2023-01-07 01:35:14 +01:00
} ,
{
"id" : 552810113 ,
"name" : "CVE-2019-5418" ,
"full_name" : "kailing0220\/CVE-2019-5418" ,
"owner" : {
"login" : "kailing0220" ,
"id" : 115863969 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/115863969?v=4" ,
"html_url" : "https:\/\/github.com\/kailing0220"
} ,
"html_url" : "https:\/\/github.com\/kailing0220\/CVE-2019-5418" ,
"description" : "Ruby on Rails是一个 Web 应用程序框架,是一个相对较新的 Web 应用程序框架,构建在 Ruby 语言之上。这个漏洞主要是由于Ruby on Rails使用了指定参数的render file来渲染应用之外的视图, 我们可以通过修改访问某控制器的请求包, 通过“…\/…\/…\/…\/”来达到路径穿越的目的,然后再通过“{{”来进行模板查询路径的闭合,使得所要访问的文件被当做外部模板来解析。" ,
"fork" : false ,
"created_at" : "2022-10-17T09:04:43Z" ,
2023-01-13 19:30:07 +01:00
"updated_at" : "2023-01-13T12:24:23Z" ,
2023-01-07 01:35:14 +01:00
"pushed_at" : "2022-10-17T09:17:42Z" ,
2023-01-13 19:30:07 +01:00
"stargazers_count" : 2 ,
"watchers_count" : 2 ,
2023-01-07 01:35:14 +01:00
"has_discussions" : false ,
"forks_count" : 0 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 0 ,
2023-01-13 19:30:07 +01:00
"watchers" : 2 ,
2023-06-19 15:46:37 +02:00
"score" : 0 ,
"subscribers_count" : 1
2019-12-08 14:19:20 +01:00
}
]