Skip to content

Commit f9763d3

Browse files
jasnowRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@1272ae6
1 parent 34ee1e7 commit f9763d3

2 files changed

Lines changed: 90 additions & 0 deletions

File tree

Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
---
2+
layout: advisory
3+
title: 'GHSA-c33f-42f2-gwcc (faraday-http-cache): Shared cache serves responses to
4+
authenticated requests to other callers'
5+
comments: false
6+
categories:
7+
- faraday-http-cache
8+
advisory:
9+
gem: faraday-http-cache
10+
ghsa: c33f-42f2-gwcc
11+
url: https://github.com/sourcelevel/faraday-http-cache/security/advisories/GHSA-c33f-42f2-gwcc
12+
title: Shared cache serves responses to authenticated requests to other callers
13+
date: 2026-09-15
14+
description: |-
15+
faraday-http-cache acts as a shared cache by default (shared_cache: true).
16+
The ByUrl strategy keys entries on method and URL and treats a cached
17+
response without a Vary header as matching every request, and the
18+
ByVary strategy relies on the origin listing Authorization in Vary.
19+
A response to a request that carried an Authorization header is
20+
therefore stored and served to later requests from different callers
21+
whenever the origin omits Vary and does not mark the response private.
22+
23+
RFC 9111 section 3.5 requires a shared cache not to reuse such a
24+
response unless it carries public, must-revalidate or s-maxage. The
25+
middleware did not implement that rule.
26+
27+
NOTE: Versions 2.0.0 through 2.7.0 were confirmed by the reporter;
28+
the 1.x line was not tested.
29+
30+
## CREDIT
31+
32+
Reported by Matthew Mongeau (Ruby Central / Project Glasswing).
33+
RFC 9111 section 3.5.
34+
cvss_v3: 6.5
35+
patched_versions:
36+
- ">= 2.8.0"
37+
related:
38+
url:
39+
- https://rubygems.org/gems/faraday-http-cache/versions/2.8.0
40+
- https://github.com/sourcelevel/faraday-http-cache/blob/master/CHANGELOG.md#280-2026-09-15
41+
- https://github.com/sourcelevel/faraday-http-cache/compare/v2.7.0...v2.8.0
42+
- https://github.com/sourcelevel/faraday-http-cache/security/advisories/GHSA-c33f-42f2-gwcc
43+
notes: |
44+
- cvss_v3 from GHSA URL.
45+
- No CVE in GHSA URL.
46+
---
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
---
2+
layout: advisory
3+
title: 'GHSA-p8jg-8p9f-pgmr (faraday-http-cache): Cache entries deserialized with
4+
JSON.load can instantiate arbitrary classes named by an origin server'
5+
comments: false
6+
categories:
7+
- faraday-http-cache
8+
advisory:
9+
gem: faraday-http-cache
10+
ghsa: p8jg-8p9f-pgmr
11+
url: https://github.com/sourcelevel/faraday-http-cache/security/advisories/GHSA-p8jg-8p9f-pgmr
12+
title: Cache entries deserialized with JSON.load can instantiate arbitrary classes
13+
named by an origin server
14+
date: 2026-09-15
15+
description: |-
16+
faraday-http-cache stores cached responses with the JSON module by
17+
default and reads them back with JSON.load, which honours the
18+
json_class key and calls json_create on the named class. Response
19+
headers are stored verbatim inside the cache entry, so an origin
20+
server that returns a json_class response header causes that class
21+
to be instantiated in the client process on the next cache hit. Any
22+
application that uses the middleware to fetch URLs it does not
23+
fully control is affected with the default configuration, through
24+
both the ByUrl and ByVary strategies.
25+
26+
NOTE: Versions 2.0.0 through 2.7.0 were confirmed by the reporter;
27+
the 1.x line was not tested but uses the same deserialization path.
28+
29+
## CREDIT
30+
31+
Reported by Matthew Mongeau (Ruby Central / Project Glasswing).
32+
cvss_v3: 8.1
33+
patched_versions:
34+
- ">= 2.8.0"
35+
related:
36+
url:
37+
- https://rubygems.org/gems/faraday-http-cache/versions/2.8.0
38+
- https://github.com/sourcelevel/faraday-http-cache/blob/master/CHANGELOG.md#280-2026-09-15
39+
- https://github.com/sourcelevel/faraday-http-cache/compare/v2.7.0...v2.8.0
40+
- https://github.com/sourcelevel/faraday-http-cache/security/advisories/GHSA-p8jg-8p9f-pgmr
41+
notes: |
42+
- cvss_v3 from GHSA URL.
43+
- No CVE in GHSA URL.
44+
---

0 commit comments

Comments
 (0)