Repository navigation
Add documentation for reporting vulnerabilities #7
Description
Activity
+1
Also how maintainers should notify users? Recommend all to sign up to a rubysec list on librelist? Subscribe an rss? Follow [ANN SEC] on ruby-talk? irc channel rubysec on freenode? Twitter?
Would be great to subscribe to gems you use for notifications.. but that's a more complicated feature. However, it's sort of already implemented in the rubygems.org site where you can subscribe to gems. Now just need to notify of vulns.
cc @drbrain
I can update the rubygems security guide once this is up to date
Maybe gems-status-web could be of help here. see:
https://github.com/jordimassaguerpla/gems-status-web/blob/master/README.md
You can get notifications on your gems (based on a Gemfile file) and the software gets alerts from different sources: mailing lists and commits on upstream.
also bundler-audit may be of your interest
@bf4 for general RubyGems security announcements, I believe rubysec-announce@googlegroups.com is the right place.
@postmodern how does one accomplish:
Request a CVE from oss-sec mailing list or reserve a CVE from MITRE
Is there a template people can use? Ditto re: osvdb email.
For requesting a CVE from MITRE: http://cve.mitre.org/cve/request_id.html
There's also http://guides.rubygems.org/security/#reporting-security-vulnerabilities as well, though it's a bit outdated (I'm working on fixing).
I submitted rubygems/guides#134 to get the rubygems guide page updated.
Basically, the steps I see that need to be followed are:
- Request a CVE (via e-mail to one of the addresses on https://github.com/RedHatProductSecurity/CVE-HOWTO#how-do-i-request-a-cve)
- Release new version of gem
- Send an email to several lists including ruby-security-ann@googlegroups.com, rubysec-announce@googlegroups.com, and oss-security@lists.openwall.com outlining the vulnerability, which versions of your gem it affects, and what actions those depending on the gem should take (generally, just what version(s) of the gem they need to update to). Make sure to use a subject that includes the gem name, some short summary of the vulnerability, and the CVE ID if you have one.
- Forward the e-mail you just sent for the above to moderators@osvdb.org to get an OSVDB ID assigned.
- Submit a PR (or just file an issue) for adding the vulnerability to https://github.com/rubysec/ruby-advisory-db/.
Could move step 4 up to after step 1... Really depends on whether blocking on MITRE / OSVDB is appropriate.
@kseifriedredhat, Sadly, MITRE is quite slow. Still waiting on CVE assignments for things I sent to oss-security@ / cve-assign@ quite a long time ago.
Document the steps to report a vulnerability.
rubysec-announce@googlegroups.com.