2019-12-08 22:19:20 +09:00
[
2021-04-05 00:10:08 +09:00
{
"id" : 175966226 ,
"name" : "CVE-2019-5418" ,
"full_name" : "mpgn\/CVE-2019-5418" ,
"owner" : {
"login" : "mpgn" ,
"id" : 5891788 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/5891788?v=4" ,
2024-10-18 09:30:24 +09:00
"html_url" : "https:\/\/github.com\/mpgn" ,
"user_view_type" : "public"
2021-04-05 00:10:08 +09:00
} ,
"html_url" : "https:\/\/github.com\/mpgn\/CVE-2019-5418" ,
"description" : "CVE-2019-5418 - File Content Disclosure on Ruby on Rails" ,
"fork" : false ,
"created_at" : "2019-03-16T11:58:18Z" ,
2024-10-05 15:31:20 +09:00
"updated_at" : "2024-10-05T05:18:16Z" ,
2021-04-06 12:11:05 +09:00
"pushed_at" : "2021-04-05T21:28:36Z" ,
2024-10-05 15:31:20 +09:00
"stargazers_count" : 193 ,
"watchers_count" : 193 ,
2022-11-08 15:19:29 +09:00
"has_discussions" : false ,
2023-05-25 09:28:33 +09:00
"forks_count" : 24 ,
2021-09-14 06:12:57 +09:00
"allow_forking" : true ,
2021-10-07 06:13:51 +09:00
"is_template" : false ,
2022-06-29 03:20:29 +09:00
"web_commit_signoff_required" : false ,
2021-10-07 06:13:51 +09:00
"topics" : [
"rails"
] ,
2021-10-02 06:13:10 +09:00
"visibility" : "public" ,
2023-05-25 09:28:33 +09:00
"forks" : 24 ,
2024-10-05 15:31:20 +09:00
"watchers" : 193 ,
2023-06-19 22:46:37 +09:00
"score" : 0 ,
2023-06-22 09:26:12 +09:00
"subscribers_count" : 4
2021-04-05 00:10:08 +09:00
} ,
2022-08-05 09:16:53 +09:00
{
"id" : 176323109 ,
"name" : "CVE-2019-5418" ,
"full_name" : "omarkurt\/CVE-2019-5418" ,
"owner" : {
"login" : "omarkurt" ,
"id" : 1712468 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/1712468?v=4" ,
2024-10-18 09:30:24 +09:00
"html_url" : "https:\/\/github.com\/omarkurt" ,
"user_view_type" : "public"
2022-08-05 09:16:53 +09:00
} ,
"html_url" : "https:\/\/github.com\/omarkurt\/CVE-2019-5418" ,
"description" : "File Content Disclosure on Rails Test Case - CVE-2019-5418" ,
"fork" : false ,
"created_at" : "2019-03-18T16:09:13Z" ,
"updated_at" : "2021-06-23T14:36:20Z" ,
"pushed_at" : "2019-03-18T16:15:25Z" ,
"stargazers_count" : 5 ,
"watchers_count" : 5 ,
2022-11-08 15:19:29 +09:00
"has_discussions" : false ,
2024-02-24 15:26:13 +09:00
"forks_count" : 0 ,
2022-08-05 09:16:53 +09:00
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [
"cve-2019-5418" ,
"ror" ,
"vulnerable-app"
] ,
"visibility" : "public" ,
2024-02-24 15:26:13 +09:00
"forks" : 0 ,
2022-08-05 09:16:53 +09:00
"watchers" : 5 ,
2023-06-19 22:46:37 +09:00
"score" : 0 ,
"subscribers_count" : 0
2022-08-05 09:16:53 +09:00
} ,
{
"id" : 176545257 ,
"name" : "CVE-2019-5418-Scanner" ,
"full_name" : "brompwnie\/CVE-2019-5418-Scanner" ,
"owner" : {
"login" : "brompwnie" ,
"id" : 8638589 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/8638589?v=4" ,
2024-10-18 09:30:24 +09:00
"html_url" : "https:\/\/github.com\/brompwnie" ,
"user_view_type" : "public"
2022-08-05 09:16:53 +09:00
} ,
"html_url" : "https:\/\/github.com\/brompwnie\/CVE-2019-5418-Scanner" ,
"description" : "A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418" ,
"fork" : false ,
"created_at" : "2019-03-19T15:38:01Z" ,
2024-08-13 09:29:46 +09:00
"updated_at" : "2024-08-12T19:46:56Z" ,
2022-08-05 09:16:53 +09:00
"pushed_at" : "2019-03-21T17:26:06Z" ,
2024-08-13 09:29:46 +09:00
"stargazers_count" : 35 ,
"watchers_count" : 35 ,
2022-11-08 15:19:29 +09:00
"has_discussions" : false ,
2022-08-05 09:16:53 +09:00
"forks_count" : 16 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 16 ,
2024-08-13 09:29:46 +09:00
"watchers" : 35 ,
2023-06-19 22:46:37 +09:00
"score" : 0 ,
2023-07-03 09:29:41 +09:00
"subscribers_count" : 3
2022-08-05 09:16:53 +09:00
} ,
2019-12-08 22:19:20 +09:00
{
2019-12-12 14:14:27 +09:00
"id" : 177236589 ,
"name" : "Rails-doubletap-RCE" ,
"full_name" : "mpgn\/Rails-doubletap-RCE" ,
2019-12-12 13:48:20 +09:00
"owner" : {
2019-12-12 14:14:27 +09:00
"login" : "mpgn" ,
"id" : 5891788 ,
2021-01-22 00:10:20 +09:00
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/5891788?v=4" ,
2024-10-18 09:30:24 +09:00
"html_url" : "https:\/\/github.com\/mpgn" ,
"user_view_type" : "public"
2019-12-12 13:48:20 +09:00
} ,
2019-12-12 14:14:27 +09:00
"html_url" : "https:\/\/github.com\/mpgn\/Rails-doubletap-RCE" ,
"description" : "RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)" ,
2019-12-12 13:48:20 +09:00
"fork" : false ,
2019-12-12 14:14:27 +09:00
"created_at" : "2019-03-23T02:52:31Z" ,
2024-09-17 21:30:38 +09:00
"updated_at" : "2024-09-17T07:15:40Z" ,
2023-01-19 21:33:38 +09:00
"pushed_at" : "2023-01-19T12:13:40Z" ,
2024-09-17 21:30:38 +09:00
"stargazers_count" : 134 ,
"watchers_count" : 134 ,
2022-11-08 15:19:29 +09:00
"has_discussions" : false ,
2024-08-15 21:30:02 +09:00
"forks_count" : 28 ,
2021-09-14 06:12:57 +09:00
"allow_forking" : true ,
2021-10-07 06:13:51 +09:00
"is_template" : false ,
2022-06-29 03:20:29 +09:00
"web_commit_signoff_required" : false ,
2021-10-07 06:13:51 +09:00
"topics" : [
"rails"
] ,
2021-10-02 06:13:10 +09:00
"visibility" : "public" ,
2024-08-15 21:30:02 +09:00
"forks" : 28 ,
2024-09-17 21:30:38 +09:00
"watchers" : 134 ,
2023-06-19 22:46:37 +09:00
"score" : 0 ,
2023-06-22 09:26:12 +09:00
"subscribers_count" : 7
2022-08-05 09:16:53 +09:00
} ,
{
"id" : 178527770 ,
"name" : "CVE-2019-5418" ,
"full_name" : "takeokunn\/CVE-2019-5418" ,
"owner" : {
"login" : "takeokunn" ,
"id" : 11222510 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/11222510?v=4" ,
2024-10-18 09:30:24 +09:00
"html_url" : "https:\/\/github.com\/takeokunn" ,
"user_view_type" : "public"
2022-08-05 09:16:53 +09:00
} ,
"html_url" : "https:\/\/github.com\/takeokunn\/CVE-2019-5418" ,
"description" : null ,
"fork" : false ,
"created_at" : "2019-03-30T07:40:11Z" ,
"updated_at" : "2019-10-24T19:07:56Z" ,
"pushed_at" : "2019-03-30T07:54:58Z" ,
"stargazers_count" : 2 ,
"watchers_count" : 2 ,
2022-11-08 15:19:29 +09:00
"has_discussions" : false ,
2022-08-05 09:16:53 +09:00
"forks_count" : 2 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 2 ,
"watchers" : 2 ,
2023-06-19 22:46:37 +09:00
"score" : 0 ,
2024-02-01 09:25:48 +09:00
"subscribers_count" : 3
2022-08-05 09:16:53 +09:00
} ,
{
"id" : 178909066 ,
"name" : "RailroadBandit" ,
"full_name" : "Bad3r\/RailroadBandit" ,
"owner" : {
"login" : "Bad3r" ,
"id" : 25513724 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/25513724?v=4" ,
2024-10-18 09:30:24 +09:00
"html_url" : "https:\/\/github.com\/Bad3r" ,
"user_view_type" : "public"
2022-08-05 09:16:53 +09:00
} ,
"html_url" : "https:\/\/github.com\/Bad3r\/RailroadBandit" ,
"description" : "a demo for Ruby on Rails CVE-2019-5418" ,
"fork" : false ,
"created_at" : "2019-04-01T17:02:57Z" ,
2024-05-23 03:29:06 +09:00
"updated_at" : "2024-05-22T12:43:49Z" ,
2022-08-05 09:16:53 +09:00
"pushed_at" : "2019-04-11T22:45:52Z" ,
2024-05-23 03:29:06 +09:00
"stargazers_count" : 3 ,
"watchers_count" : 3 ,
2022-11-08 15:19:29 +09:00
"has_discussions" : false ,
2022-08-05 09:16:53 +09:00
"forks_count" : 0 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 0 ,
2024-05-23 03:29:06 +09:00
"watchers" : 3 ,
2023-06-19 22:46:37 +09:00
"score" : 0 ,
"subscribers_count" : 1
2022-08-05 09:16:53 +09:00
} ,
2022-10-17 21:17:39 +09:00
{
2023-01-02 21:13:52 +09:00
"id" : 212888337 ,
"name" : "CVE-2019-5418-Rails3" ,
"full_name" : "ztgrace\/CVE-2019-5418-Rails3" ,
"owner" : {
"login" : "ztgrace" ,
"id" : 2554037 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/2554037?v=4" ,
2024-10-18 09:30:24 +09:00
"html_url" : "https:\/\/github.com\/ztgrace" ,
"user_view_type" : "public"
2023-01-02 21:13:52 +09:00
} ,
"html_url" : "https:\/\/github.com\/ztgrace\/CVE-2019-5418-Rails3" ,
"description" : "Rails 3 PoC of CVE-2019-5418" ,
"fork" : false ,
"created_at" : "2019-10-04T19:28:10Z" ,
"updated_at" : "2019-10-04T19:29:56Z" ,
2023-07-14 09:28:00 +09:00
"pushed_at" : "2023-07-13T22:14:58Z" ,
2023-01-02 21:13:52 +09:00
"stargazers_count" : 0 ,
"watchers_count" : 0 ,
"has_discussions" : false ,
"forks_count" : 1 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 1 ,
"watchers" : 0 ,
2023-06-19 22:46:37 +09:00
"score" : 0 ,
"subscribers_count" : 2
2023-01-02 21:13:52 +09:00
} ,
{
"id" : 222660643 ,
2022-10-17 21:17:39 +09:00
"name" : "CVE-2019-5418" ,
2023-01-02 21:13:52 +09:00
"full_name" : "random-robbie\/CVE-2019-5418" ,
2022-10-17 21:17:39 +09:00
"owner" : {
2023-01-02 21:13:52 +09:00
"login" : "random-robbie" ,
"id" : 4902869 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/4902869?v=4" ,
2024-10-18 09:30:24 +09:00
"html_url" : "https:\/\/github.com\/random-robbie" ,
"user_view_type" : "public"
2022-10-17 21:17:39 +09:00
} ,
2023-01-02 21:13:52 +09:00
"html_url" : "https:\/\/github.com\/random-robbie\/CVE-2019-5418" ,
"description" : null ,
2022-10-17 21:17:39 +09:00
"fork" : false ,
2023-01-02 21:13:52 +09:00
"created_at" : "2019-11-19T09:40:06Z" ,
"updated_at" : "2021-04-26T19:41:51Z" ,
"pushed_at" : "2019-11-19T09:41:18Z" ,
"stargazers_count" : 5 ,
"watchers_count" : 5 ,
2022-11-08 15:19:29 +09:00
"has_discussions" : false ,
2023-01-02 21:13:52 +09:00
"forks_count" : 1 ,
2022-10-17 21:17:39 +09:00
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
2023-01-02 21:13:52 +09:00
"forks" : 1 ,
"watchers" : 5 ,
2023-06-19 22:46:37 +09:00
"score" : 0 ,
2023-06-25 09:26:29 +09:00
"subscribers_count" : 3
2023-01-07 09:35:14 +09:00
} ,
{
"id" : 552810113 ,
"name" : "CVE-2019-5418" ,
"full_name" : "kailing0220\/CVE-2019-5418" ,
"owner" : {
"login" : "kailing0220" ,
"id" : 115863969 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/115863969?v=4" ,
2024-10-18 09:30:24 +09:00
"html_url" : "https:\/\/github.com\/kailing0220" ,
"user_view_type" : "public"
2023-01-07 09:35:14 +09:00
} ,
"html_url" : "https:\/\/github.com\/kailing0220\/CVE-2019-5418" ,
"description" : "Ruby on Rails是一个 Web 应用程序框架,是一个相对较新的 Web 应用程序框架,构建在 Ruby 语言之上。这个漏洞主要是由于Ruby on Rails使用了指定参数的render file来渲染应用之外的视图, 我们可以通过修改访问某控制器的请求包, 通过“…\/…\/…\/…\/”来达到路径穿越的目的,然后再通过“{{”来进行模板查询路径的闭合,使得所要访问的文件被当做外部模板来解析。" ,
"fork" : false ,
"created_at" : "2022-10-17T09:04:43Z" ,
2023-01-14 03:30:07 +09:00
"updated_at" : "2023-01-13T12:24:23Z" ,
2023-01-07 09:35:14 +09:00
"pushed_at" : "2022-10-17T09:17:42Z" ,
2023-01-14 03:30:07 +09:00
"stargazers_count" : 2 ,
"watchers_count" : 2 ,
2023-01-07 09:35:14 +09:00
"has_discussions" : false ,
"forks_count" : 0 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 0 ,
2023-01-14 03:30:07 +09:00
"watchers" : 2 ,
2023-06-19 22:46:37 +09:00
"score" : 0 ,
"subscribers_count" : 1
2019-12-08 22:19:20 +09:00
}
]