Skip to content

Add documentation for reporting vulnerabilities #7

Description

@postmodern

Document the steps to report a vulnerability.

  1. OSVDB: email moderators@osvdb.org and/or message @osvdb on GitHub or Twitter.
  2. Request a CVE from oss-sec mailing list or reserve a CVE from MITRE.
  3. Once OSVDB or CVE have been obtained, send advisory to rubysec-announce@googlegroups.com.

Activity

  1. jordimassaguerpla commented on Dec 12, 2013

    @jordimassaguerpla

    +1

  2. bf4 commented on Dec 12, 2013

    @bf4

    Also how maintainers should notify users? Recommend all to sign up to a rubysec list on librelist? Subscribe an rss? Follow [ANN SEC] on ruby-talk? irc channel rubysec on freenode? Twitter?

    Would be great to subscribe to gems you use for notifications.. but that's a more complicated feature. However, it's sort of already implemented in the rubygems.org site where you can subscribe to gems. Now just need to notify of vulns.

    cc @drbrain

  3. bf4 commented on Dec 12, 2013

    @bf4

    I can update the rubygems security guide once this is up to date

  4. jordimassaguerpla commented on Dec 12, 2013

    @jordimassaguerpla

    Maybe gems-status-web could be of help here. see:

    https://github.com/jordimassaguerpla/gems-status-web/blob/master/README.md

    You can get notifications on your gems (based on a Gemfile file) and the software gets alerts from different sources: mailing lists and commits on upstream.

  5. dwradcliffe commented on Dec 12, 2013

    @dwradcliffe
    Contributor

    For the record, there are several hosted tools that can help keep users updated too. (Gemnasium and gemcanary)

  6. jordimassaguerpla commented on Dec 12, 2013

    @jordimassaguerpla

    also bundler-audit may be of your interest

    https://github.com/postmodern/bundler-audit

  7. postmodern commented on Dec 12, 2013

    @postmodern
    MemberAuthor

    @bf4 for general RubyGems security announcements, I believe rubysec-announce@googlegroups.com is the right place.

  8. phillmv commented on Dec 17, 2013

    @phillmv
    Member

    @postmodern how does one accomplish:

    Request a CVE from oss-sec mailing list or reserve a CVE from MITRE

    Is there a template people can use? Ditto re: osvdb email.

  9. postmodern commented on Dec 17, 2013

    @postmodern
    MemberAuthor

    For requesting a CVE from MITRE: http://cve.mitre.org/cve/request_id.html

  10. reedloden commented on Jul 15, 2015

    @reedloden
    Member

    There's also http://guides.rubygems.org/security/#reporting-security-vulnerabilities as well, though it's a bit outdated (I'm working on fixing).

  11. reedloden commented on Aug 3, 2015

    @reedloden
    Member

    I submitted rubygems/guides#134 to get the rubygems guide page updated.

    Basically, the steps I see that need to be followed are:

    1. Request a CVE (via e-mail to one of the addresses on https://github.com/RedHatProductSecurity/CVE-HOWTO#how-do-i-request-a-cve)
    2. Release new version of gem
    3. Send an email to several lists including ruby-security-ann@googlegroups.com, rubysec-announce@googlegroups.com, and oss-security@lists.openwall.com outlining the vulnerability, which versions of your gem it affects, and what actions those depending on the gem should take (generally, just what version(s) of the gem they need to update to). Make sure to use a subject that includes the gem name, some short summary of the vulnerability, and the CVE ID if you have one.
    4. Forward the e-mail you just sent for the above to moderators@osvdb.org to get an OSVDB ID assigned.
    5. Submit a PR (or just file an issue) for adding the vulnerability to https://github.com/rubysec/ruby-advisory-db/.

    Could move step 4 up to after step 1... Really depends on whether blocking on MITRE / OSVDB is appropriate.

  12. reedloden commented on Aug 3, 2015

    @reedloden
    Member

    @kseifriedredhat, Sadly, MITRE is quite slow. Still waiting on CVE assignments for things I sent to oss-security@ / cve-assign@ quite a long time ago.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions