Skip to content

v5.0.7

Choose a tag to compare

@petergoldstein petergoldstein released this 24 Sep 23:09
· 76 commits to main since this release

Security release. Fixes GHSA-6wmv-xq9m-fmp7, a memcached command injection through numeric arguments. Upgrading is recommended.

Security:

  • Fix memcached command injection through numeric arguments (GHSA-6wmv-xq9m-fmp7)
    • The default argument of incr/decr, and fetch_with_lock's lock_ttl and recache_threshold, were written into the meta protocol command without conversion, so a String containing CRLF injected additional memcached commands (e.g. set, flush_all) on the connection
    • These arguments must now be Integers, or Strings of decimal digits; anything else raises ArgumentError before a request is sent
    • As defense in depth, RequestFormatter now converts every numeric flag it writes (D, J, N, R, T) to an Integer
    • Thanks to oss-security-shop for the report