Coder Social home page Coder Social logo

Memory / Reference Leak about grape HOT 2 CLOSED

ruby-grape avatar ruby-grape commented on May 30, 2024
Memory / Reference Leak

from grape.

Comments (2)

bmorton avatar bmorton commented on May 30, 2024

aren't the only params stored in there the ones that are specifically defined in the route or is there another way to populate that?

from grape.

aq1018 avatar aq1018 commented on May 30, 2024

In this line:

https://github.com/intridea/grape/blob/master/lib/grape/endpoint.rb#L31

request is a Rack::Request. I am under the assumption that request.params will parse url query string and form posts into the params hash.

Under this assumption, I can query the server repeatedly with random query strings. The query string then gets parsed by rack and turned into hashes. Then you convert the keys of that hash containing query string into symbols in L33.

This is not safe, because I can query your server with randomly generated key value pairs in query string, and your code will convert all of them into symbols. If doing it long enough, the attacker can exhaust all memory on the server by bloating your app to death.

from grape.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.