fix: prevent RCE through the "lookup"-helper

- The "lookup" helper could also be used to run a remote code execution
  by manipulating the template. The same check as for regular
  path queries now also is done in the "lookup"-helper
This commit is contained in:
Nils Knappmeier
2019-04-11 17:46:27 +02:00
parent c454d946e3
commit cd38583216
2 changed files with 14 additions and 1 deletions
+7 -1
View File
@@ -1,5 +1,11 @@
export default function(instance) { export default function(instance) {
instance.registerHelper('lookup', function(obj, field) { instance.registerHelper('lookup', function(obj, field) {
return obj && obj[field]; if (!obj) {
return obj;
}
if (field === 'constructor' && !obj.propertyIsEnumerable(field)) {
return undefined;
}
return obj[field];
}); });
} }
+7
View File
@@ -2,12 +2,16 @@ describe('security issues', function() {
describe('GH-1495: Prevent Remote Code Execution via constructor', function() { describe('GH-1495: Prevent Remote Code Execution via constructor', function() {
it('should not allow constructors to be accessed', function() { it('should not allow constructors to be accessed', function() {
shouldCompileTo('{{constructor.name}}', {}, ''); shouldCompileTo('{{constructor.name}}', {}, '');
shouldCompileTo('{{lookup (lookup this "constructor") "name"}}', {}, '');
}); });
it('should allow the "constructor" property to be accessed if it is enumerable', function() { it('should allow the "constructor" property to be accessed if it is enumerable', function() {
shouldCompileTo('{{constructor.name}}', {'constructor': { shouldCompileTo('{{constructor.name}}', {'constructor': {
'name': 'here we go' 'name': 'here we go'
}}, 'here we go'); }}, 'here we go');
shouldCompileTo('{{lookup (lookup this "constructor") "name"}}', {'constructor': {
'name': 'here we go'
}}, 'here we go');
}); });
it('should allow prototype properties that are not constructors', function() { it('should allow prototype properties that are not constructors', function() {
@@ -23,6 +27,9 @@ describe('security issues', function() {
shouldCompileTo('{{#with this as |obj|}}{{obj.abc}}{{/with}}', shouldCompileTo('{{#with this as |obj|}}{{obj.abc}}{{/with}}',
new TestClass(), 'xyz'); new TestClass(), 'xyz');
shouldCompileTo('{{#with this as |obj|}}{{lookup obj "abc"}}{{/with}}',
new TestClass(), 'xyz');
}); });
}); });
}); });