53 lines
2.3 KiB
Diff
53 lines
2.3 KiB
Diff
diff -up vim91/runtime/ftplugin/cucumber.vim.cucumber-code-inject vim91/runtime/ftplugin/cucumber.vim
|
|
--- vim91/runtime/ftplugin/cucumber.vim.cucumber-code-inject 2024-02-09 06:33:54.000000000 +0100
|
|
+++ vim91/runtime/ftplugin/cucumber.vim 2026-06-30 15:39:27.581293444 +0200
|
|
@@ -96,7 +96,8 @@ function! s:stepmatch(receiver,target)
|
|
catch
|
|
endtry
|
|
if has("ruby") && pattern !~ '\\\@<!#{'
|
|
- ruby VIM.command("return #{if (begin; Kernel.eval('/'+VIM.evaluate('pattern')+'/'); rescue SyntaxError; end) === VIM.evaluate('a:target') then 1 else 0 end}")
|
|
+ " Use Regexp.new, so the pattern stays untrusted data and cannot inject Ruby
|
|
+ ruby VIM.command("return #{if (begin; Regexp.new(VIM.evaluate('pattern')); rescue RegexpError; end) === VIM.evaluate('a:target') then 1 else 0 end}")
|
|
else
|
|
return 0
|
|
endif
|
|
diff -up vim91/src/testdir/test_filetype.vim.cucumber-code-inject vim91/src/testdir/test_filetype.vim
|
|
--- vim91/src/testdir/test_filetype.vim.cucumber-code-inject 2024-02-09 06:33:54.000000000 +0100
|
|
+++ vim91/src/testdir/test_filetype.vim 2026-06-30 15:39:58.032115889 +0200
|
|
@@ -2413,4 +2413,35 @@ func Test_def_file()
|
|
filetype off
|
|
endfunc
|
|
|
|
+func Test_cucumber_code_injection()
|
|
+ source check.vim
|
|
+ CheckFeature ruby
|
|
+ filetype plugin on
|
|
+
|
|
+ call mkdir('Xcucu/features/step_definitions', 'pR')
|
|
+ call writefile([
|
|
+ \ 'Feature: demo',
|
|
+ \ ' Scenario: trigger',
|
|
+ \ ' Given xyzzy',
|
|
+ \ ], 'Xcucu/features/test.feature')
|
|
+ let marker = getcwd() . '/Xcucu/MARKER'
|
|
+ " Malicious step: terminates the regex literal, injects Ruby system(),
|
|
+ " comments the trailing slash. With the fix, the pattern is passed to
|
|
+ " Regexp.new() instead of Kernel.eval() and the payload is inert.
|
|
+ call writefile([
|
|
+ \ 'Given /xyzzy/; system("touch ' . marker . '"); #/ do',
|
|
+ \ 'end',
|
|
+ \ ], 'Xcucu/features/step_definitions/poc.rb')
|
|
+
|
|
+ new Xcucu/features/test.feature
|
|
+ call assert_equal('cucumber', &filetype)
|
|
+ call cursor(3, 1)
|
|
+ " Triggers s:jump -> s:steps -> s:stepmatch on every discovered step,
|
|
+ " including the malicious one. Suppress preview and error messages.
|
|
+ silent! normal [d
|
|
+ call assert_false(filereadable(marker), 'Ruby injection executed')
|
|
+ bwipe!
|
|
+ filetype plugin off
|
|
+endfunc
|
|
+
|
|
" vim: shiftwidth=2 sts=2 expandtab
|