diff --git a/CHANGELOG.md b/CHANGELOG.md index 9e5ac7e43..e74cca0e1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,10 @@ All notable changes to this project will be documented in this file. For info on how to format all future additions to this file please reference [Keep A Changelog](https://keepachangelog.com/en/1.0.0/). +## [2.2.3] - 2020-02-11 + +- [CVE-2020-8184] Only decode cookie values + ## [2.2.2] - 2020-02-11 ### Fixed diff --git a/lib/rack/utils.rb b/lib/rack/utils.rb index f033c900d..d3b3b1d42 100644 --- a/lib/rack/utils.rb +++ b/lib/rack/utils.rb @@ -212,8 +212,12 @@ def parse_cookies_header(header) # The syntax for cookie headers only supports semicolons # User Agent -> Server == # Cookie: SID=31d4d96e407aad42; lang=en-US - cookies = parse_query(header, ';') { |s| unescape(s) rescue s } - cookies.each_with_object({}) { |(k, v), hash| hash[k] = Array === v ? v.first : v } + return {} unless header + header.split(/[;] */n).each_with_object({}) do |cookie, cookies| + next if cookie.empty? + key, value = cookie.split('=', 2) + cookies[key] = (unescape(value) rescue value) unless cookies.key?(key) + end end def add_cookie_to_header(header, key, value) diff --git a/lib/rack/version.rb b/lib/rack/version.rb index 06f7b2cdc..aad9c5915 100644 --- a/lib/rack/version.rb +++ b/lib/rack/version.rb @@ -20,7 +20,7 @@ def self.version VERSION.join(".") end - RELEASE = "2.2.2" + RELEASE = "2.2.3" # Return the Rack release as a dotted string. def self.release diff --git a/test/spec_utils.rb b/test/spec_utils.rb index b39f4a00d..273dc6c1f 100644 --- a/test/spec_utils.rb +++ b/test/spec_utils.rb @@ -524,6 +524,10 @@ def initialize(*) env = Rack::MockRequest.env_for("", "HTTP_COOKIE" => "foo=bar").freeze Rack::Utils.parse_cookies(env).must_equal({ "foo" => "bar" }) + + env = Rack::MockRequest.env_for("", "HTTP_COOKIE" => "%66oo=baz;foo=bar") + cookies = Rack::Utils.parse_cookies(env) + cookies.must_equal({ "%66oo" => "baz", "foo" => "bar" }) end it "adds new cookies to nil header" do