{"id":"GHSA-v222-6mr4-qj29","summary":"Command Injection vulnerability in asciidoctor-include-ext","details":"### Impact\n\nApplications using [Asciidoctor (Ruby)](https://github.com/asciidoctor/asciidoctor) with [asciidoctor-include-ext](https://github.com/jirutka/asciidoctor-include-ext) (prior to version 0.4.0), which render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. ~~This attack is possible even when `allow-uri-read` is disabled!~~ (EDIT: it’s not)\n\n\n### Patches\n\nThe vulnerability has been fixed in commit c7ea001 (and further improved in cbaccf3), which is included in version [0.4.0](https://rubygems.org/gems/asciidoctor-include-ext/versions/0.4.0).\n\n### Workarounds\n\n```rb\nrequire 'asciidoctor/include_ext'\n\nclass Asciidoctor::IncludeExt::IncludeProcessor\n  # Overrides superclass private method to mitigate Command Injection\n  # vulnerability in asciidoctor-include-ext \u003c0.4.0.\n  def target_uri?(target)\n    target.downcase.start_with?('http://', 'https://') \\\n      && URI.parse(target).is_a?(URI::HTTP)\n  rescue URI::InvalidURIError\n    false\n  end\nend\n```\n\n### References\n\n* https://sakurity.com/blog/2015/02/28/openuri.html\n\n### Credits\n\nThis vulnerability was discovered by Joern Schneeweisz from the GitLab Security Research Team.\n\n\n### For more information\n\nSee commit message c7ea001.\n\nIf you have any questions or comments about this advisory open an issue in [jirutka/asciidoctor-include-ext](https://github.com/jirutka/asciidoctor-include-ext/issues/).","aliases":["CVE-2022-24803"],"modified":"2023-11-08T04:08:37.142159Z","published":"2022-03-31T23:27:15Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-03-31T23:27:15Z","nvd_published_at":"2022-04-01T00:15:00Z","cwe_ids":["CWE-78"]},"references":[{"type":"WEB","url":"https://github.com/jirutka/asciidoctor-include-ext/security/advisories/GHSA-v222-6mr4-qj29"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24803"},{"type":"WEB","url":"https://github.com/jirutka/asciidoctor-include-ext/commit/c7ea001a597c7033575342c51483dab7b87ae155"},{"type":"WEB","url":"https://github.com/jirutka/asciidoctor-include-ext/commit/cbaccf3de533cbca224bf61d0b74e4b84d41d8ee"},{"type":"PACKAGE","url":"https://github.com/jirutka/asciidoctor-include-ext"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/asciidoctor-include-ext/CVE-2022-24803.yml"}],"affected":[{"package":{"name":"asciidoctor-include-ext","ecosystem":"RubyGems","purl":"pkg:gem/asciidoctor-include-ext"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.0"}]}],"versions":["0.1.0","0.1.1","0.2.0","0.3.0","0.3.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-v222-6mr4-qj29/GHSA-v222-6mr4-qj29.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}