13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
|
# File 'lib/brakeman/checks/check_ransack.rb', line 13
def check_ransack_calls
tracker.find_call(method: :ransack, nested: true).each do |result|
next unless original? result
call = result[:call]
arg = call.first_arg
class_name = result[:chain].first
next if ransackable_allow_list?(class_name)
if input = has_immediate_user_input?(arg)
confidence = if tracker.find_class(class_name).nil?
confidence = :low
elsif result[:location][:file].relative.include? 'admin'
confidence = :medium
else
confidence = :high
end
message = msg('Unrestricted search using ', msg_code('ransack'), ' library called with ', msg_input(input), '. Limit search by defining ', msg_code('ransackable_attributes'), ' and ', msg_code('ransackable_associations'), ' methods in class or upgrade Ransack to version 4.0.0 or newer')
warn result: result,
warning_type: 'Missing Authorization',
warning_code: :ransack_search,
message: message,
user_input: input,
confidence: confidence,
cwe_id: [862],
link: 'https://positive.security/blog/ransack-data-exfiltration'
end
end
end
|