From ee27188b59d174f4db16d2ce4b7cd2181ea93517 Mon Sep 17 00:00:00 2001 From: Martin Cech Date: Mon, 23 Oct 2017 17:15:52 -0400 Subject: [PATCH] add security release notes --- .../scripts/libs/jquery/jquery.complexify.js | 192 ++++++++++ doc/source/api/api.rst | 348 ++++++++++++++++++ doc/source/api/ts_api.rst | 68 ++++ doc/source/releases/17.09_announce.rst | 69 +++- 4 files changed, 676 insertions(+), 1 deletion(-) create mode 100644 client/galaxy/scripts/libs/jquery/jquery.complexify.js create mode 100644 doc/source/api/api.rst create mode 100644 doc/source/api/ts_api.rst diff --git a/client/galaxy/scripts/libs/jquery/jquery.complexify.js b/client/galaxy/scripts/libs/jquery/jquery.complexify.js new file mode 100644 index 00000000000..9d09a8d61de --- /dev/null +++ b/client/galaxy/scripts/libs/jquery/jquery.complexify.js @@ -0,0 +1,192 @@ +/* + http://github.com/danpalmer/jquery.complexify.js + + This code is distributed under the WTFPL v2: +*/ +(function ($) { + + $.fn.extend({ + complexify: function(options, callback) { + + var MIN_COMPLEXITY = 49; // 12 chars with Upper, Lower and Number + var MAX_COMPLEXITY = 120; // 25 chars, all charsets + var CHARSETS = [ + // Commonly Used + //////////////////// + [0x0020, 0x0020], // Space + [0x0030, 0x0039], // Numbers + [0x0041, 0x005A], // Uppercase + [0x0061, 0x007A], // Lowercase + [0x0021, 0x002F], // Punctuation + [0x003A, 0x0040], // Punctuation + [0x005B, 0x0060], // Punctuation + [0x007B, 0x007E], // Punctuation + // Everything Else + //////////////////// + [0x0080, 0x00FF], // Latin-1 Supplement + [0x0100, 0x017F], // Latin Extended-A + [0x0180, 0x024F], // Latin Extended-B + [0x0250, 0x02AF], // IPA Extensions + [0x02B0, 0x02FF], // Spacing Modifier Letters + [0x0300, 0x036F], // Combining Diacritical Marks + [0x0370, 0x03FF], // Greek + [0x0400, 0x04FF], // Cyrillic + [0x0530, 0x058F], // Armenian + [0x0590, 0x05FF], // Hebrew + [0x0600, 0x06FF], // Arabic + [0x0700, 0x074F], // Syriac + [0x0780, 0x07BF], // Thaana + [0x0900, 0x097F], // Devanagari + [0x0980, 0x09FF], // Bengali + [0x0A00, 0x0A7F], // Gurmukhi + [0x0A80, 0x0AFF], // Gujarati + [0x0B00, 0x0B7F], // Oriya + [0x0B80, 0x0BFF], // Tamil + [0x0C00, 0x0C7F], // Telugu + [0x0C80, 0x0CFF], // Kannada + [0x0D00, 0x0D7F], // Malayalam + [0x0D80, 0x0DFF], // Sinhala + [0x0E00, 0x0E7F], // Thai + [0x0E80, 0x0EFF], // Lao + [0x0F00, 0x0FFF], // Tibetan + [0x1000, 0x109F], // Myanmar + [0x10A0, 0x10FF], // Georgian + [0x1100, 0x11FF], // Hangul Jamo + [0x1200, 0x137F], // Ethiopic + [0x13A0, 0x13FF], // Cherokee + [0x1400, 0x167F], // Unified Canadian Aboriginal Syllabics + [0x1680, 0x169F], // Ogham + [0x16A0, 0x16FF], // Runic + [0x1780, 0x17FF], // Khmer + [0x1800, 0x18AF], // Mongolian + [0x1E00, 0x1EFF], // Latin Extended Additional + [0x1F00, 0x1FFF], // Greek Extended + [0x2000, 0x206F], // General Punctuation + [0x2070, 0x209F], // Superscripts and Subscripts + [0x20A0, 0x20CF], // Currency Symbols + [0x20D0, 0x20FF], // Combining Marks for Symbols + [0x2100, 0x214F], // Letterlike Symbols + [0x2150, 0x218F], // Number Forms + [0x2190, 0x21FF], // Arrows + [0x2200, 0x22FF], // Mathematical Operators + [0x2300, 0x23FF], // Miscellaneous Technical + [0x2400, 0x243F], // Control Pictures + [0x2440, 0x245F], // Optical Character Recognition + [0x2460, 0x24FF], // Enclosed Alphanumerics + [0x2500, 0x257F], // Box Drawing + [0x2580, 0x259F], // Block Elements + [0x25A0, 0x25FF], // Geometric Shapes + [0x2600, 0x26FF], // Miscellaneous Symbols + [0x2700, 0x27BF], // Dingbats + [0x2800, 0x28FF], // Braille Patterns + [0x2E80, 0x2EFF], // CJK Radicals Supplement + [0x2F00, 0x2FDF], // Kangxi Radicals + [0x2FF0, 0x2FFF], // Ideographic Description Characters + [0x3000, 0x303F], // CJK Symbols and Punctuation + [0x3040, 0x309F], // Hiragana + [0x30A0, 0x30FF], // Katakana + [0x3100, 0x312F], // Bopomofo + [0x3130, 0x318F], // Hangul Compatibility Jamo + [0x3190, 0x319F], // Kanbun + [0x31A0, 0x31BF], // Bopomofo Extended + [0x3200, 0x32FF], // Enclosed CJK Letters and Months + [0x3300, 0x33FF], // CJK Compatibility + [0x3400, 0x4DB5], // CJK Unified Ideographs Extension A + [0x4E00, 0x9FFF], // CJK Unified Ideographs + [0xA000, 0xA48F], // Yi Syllables + [0xA490, 0xA4CF], // Yi Radicals + [0xAC00, 0xD7A3], // Hangul Syllables + [0xD800, 0xDB7F], // High Surrogates + [0xDB80, 0xDBFF], // High Private Use Surrogates + [0xDC00, 0xDFFF], // Low Surrogates + [0xE000, 0xF8FF], // Private Use + [0xF900, 0xFAFF], // CJK Compatibility Ideographs + [0xFB00, 0xFB4F], // Alphabetic Presentation Forms + [0xFB50, 0xFDFF], // Arabic Presentation Forms-A + [0xFE20, 0xFE2F], // Combining Half Marks + [0xFE30, 0xFE4F], // CJK Compatibility Forms + [0xFE50, 0xFE6F], // Small Form Variants + [0xFE70, 0xFEFE], // Arabic Presentation Forms-B + [0xFEFF, 0xFEFF], // Specials + [0xFF00, 0xFFEF], // Halfwidth and Fullwidth Forms + [0xFFF0, 0xFFFD] // Specials + ]; + + var defaults = { + minimumChars: 8, + strengthScaleFactor: 1, + bannedPasswords: window.COMPLEXIFY_BANLIST || [], + banMode: 'strict' // (strict|loose) + }; + + if($.isFunction(options) && !callback) { + callback = options; + options = {}; + } + + options = $.extend(defaults, options); + + function additionalComplexityForCharset(str, charset) { + for (var i = str.length - 1; i >= 0; i--) { + if (charset[0] <= str.charCodeAt(i) && str.charCodeAt(i) <= charset[1]) { + return charset[1] - charset[0] + 1; + } + } + return 0; + } + + function inBanlist(str) { + if (options.banMode === 'strict') { + for (var i = 0; i < options.bannedPasswords.length; i++) { + if (str.toLowerCase().indexOf(options.bannedPasswords[i].toLowerCase()) !== -1) { + return true; + } + } + return false; + } else { + return $.inArray(str, options.bannedPasswords) > -1 ? true : false; + } + } + + function evaluateSecurity() { + var password = $(this).val(); + var complexity = 0, valid = false; + + // Reset complexity to 0 when banned password is found + if (!inBanlist(password)) { + + // Add character complexity + for (var i = CHARSETS.length - 1; i >= 0; i--) { + complexity += additionalComplexityForCharset(password, CHARSETS[i]); + } + + } else { + complexity = 1; + } + + // Use natural log to produce linear scale + complexity = Math.log(Math.pow(complexity, password.length)) * (1/options.strengthScaleFactor); + + valid = (complexity > MIN_COMPLEXITY && password.length >= options.minimumChars); + + // Scale to percentage, so it can be used for a progress bar + complexity = (complexity / MAX_COMPLEXITY) * 100; + complexity = (complexity > 100) ? 100 : complexity; + + callback.call(this, valid, complexity); + } + + this.each(function () { + if($(this).val()) { + evaluateSecurity.apply(this); + } + }); + + return this.each(function () { + $(this).bind('keyup focus input propertychange mouseup', evaluateSecurity); + }); + + } + }); + +})(jQuery); diff --git a/doc/source/api/api.rst b/doc/source/api/api.rst new file mode 100644 index 00000000000..d7ae13cc564 --- /dev/null +++ b/doc/source/api/api.rst @@ -0,0 +1,348 @@ +Galaxy API +========== + +annotations module +------------------------------------------------ + +.. automodule:: galaxy.webapps.galaxy.api.annotations + :members: + :undoc-members: + :show-inheritance: + +authenticate module +------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.authenticate + :members: + :undoc-members: + :show-inheritance: + +configuration module +-------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.configuration + :members: + :undoc-members: + :show-inheritance: + +dataset\_collections module +--------------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.dataset_collections + :members: + :undoc-members: + :show-inheritance: + +datasets module +--------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.datasets + :members: + :undoc-members: + :show-inheritance: + +datatypes module +---------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.datatypes + :members: + :undoc-members: + :show-inheritance: + +extended\_metadata module +------------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.extended_metadata + :members: + :undoc-members: + :show-inheritance: + +folder\_contents module +----------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.folder_contents + :members: + :undoc-members: + :show-inheritance: + +folders module +-------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.folders + :members: + :undoc-members: + :show-inheritance: + +forms module +------------------------------------------ + +.. automodule:: galaxy.webapps.galaxy.api.forms + :members: + :undoc-members: + :show-inheritance: + +genomes module +-------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.genomes + :members: + :undoc-members: + :show-inheritance: + +group\_roles module +------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.group_roles + :members: + :undoc-members: + :show-inheritance: + +group\_users module +------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.group_users + :members: + :undoc-members: + :show-inheritance: + +groups module +------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.groups + :members: + :undoc-members: + :show-inheritance: + +histories module +---------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.histories + :members: + :undoc-members: + :show-inheritance: + +history\_contents module +------------------------------------------------------ + +.. automodule:: galaxy.webapps.galaxy.api.history_contents + :members: + :undoc-members: + :show-inheritance: + +item\_tags module +----------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.item_tags + :members: + :undoc-members: + :show-inheritance: + +job\_files module +----------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.job_files + :members: + :undoc-members: + :show-inheritance: + +jobs module +----------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.jobs + :members: + :undoc-members: + :show-inheritance: + +lda\_datasets module +-------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.lda_datasets + :members: + :undoc-members: + :show-inheritance: + +libraries module +---------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.libraries + :members: + :undoc-members: + :show-inheritance: + +library\_contents module +------------------------------------------------------ + +.. automodule:: galaxy.webapps.galaxy.api.library_contents + :members: + :undoc-members: + :show-inheritance: + +metrics module +-------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.metrics + :members: + :undoc-members: + :show-inheritance: + +page\_revisions module +---------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.page_revisions + :members: + :undoc-members: + :show-inheritance: + +pages module +------------------------------------------ + +.. automodule:: galaxy.webapps.galaxy.api.pages + :members: + :undoc-members: + :show-inheritance: + +provenance module +----------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.provenance + :members: + :undoc-members: + :show-inheritance: + +quotas module +------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.quotas + :members: + :undoc-members: + :show-inheritance: + +remote\_files module +-------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.remote_files + :members: + :undoc-members: + :show-inheritance: + +request\_types module +--------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.request_types + :members: + :undoc-members: + :show-inheritance: + +requests module +--------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.requests + :members: + :undoc-members: + :show-inheritance: + +roles module +------------------------------------------ + +.. automodule:: galaxy.webapps.galaxy.api.roles + :members: + :undoc-members: + :show-inheritance: + +samples module +-------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.samples + :members: + :undoc-members: + :show-inheritance: + +search module +------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.search + :members: + :undoc-members: + :show-inheritance: + +tool\_data module +----------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.tool_data + :members: + :undoc-members: + :show-inheritance: + +tool\_dependencies module +------------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.tool_dependencies + :members: + :undoc-members: + :show-inheritance: + +tool\_shed\_repositories module +------------------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.tool_shed_repositories + :members: + :undoc-members: + :show-inheritance: + +tools module +------------------------------------------ + +.. automodule:: galaxy.webapps.galaxy.api.tools + :members: + :undoc-members: + :show-inheritance: + +toolshed module +--------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.toolshed + :members: + :undoc-members: + :show-inheritance: + +tours module +------------------------------------------ + +.. automodule:: galaxy.webapps.galaxy.api.tours + :members: + :undoc-members: + :show-inheritance: + +users module +------------------------------------------ + +.. automodule:: galaxy.webapps.galaxy.api.users + :members: + :undoc-members: + :show-inheritance: + +visualizations module +--------------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.visualizations + :members: + :undoc-members: + :show-inheritance: + +webhooks module +--------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.webhooks + :members: + :undoc-members: + :show-inheritance: + +workflows module +---------------------------------------------- + +.. automodule:: galaxy.webapps.galaxy.api.workflows + :members: + :undoc-members: + :show-inheritance: + + diff --git a/doc/source/api/ts_api.rst b/doc/source/api/ts_api.rst new file mode 100644 index 00000000000..c8257587a17 --- /dev/null +++ b/doc/source/api/ts_api.rst @@ -0,0 +1,68 @@ +Tool Shed API +============= + +authenticate module +----------------------------------------------------- + +.. automodule:: galaxy.webapps.tool_shed.api.authenticate + :members: + :undoc-members: + :show-inheritance: + +categories module +--------------------------------------------------- + +.. automodule:: galaxy.webapps.tool_shed.api.categories + :members: + :undoc-members: + :show-inheritance: + +configuration module +------------------------------------------------------ + +.. automodule:: galaxy.webapps.tool_shed.api.configuration + :members: + :undoc-members: + :show-inheritance: + +groups module +----------------------------------------------- + +.. automodule:: galaxy.webapps.tool_shed.api.groups + :members: + :undoc-members: + :show-inheritance: + +repositories module +----------------------------------------------------- + +.. automodule:: galaxy.webapps.tool_shed.api.repositories + :members: + :undoc-members: + :show-inheritance: + +repository\_revisions module +-------------------------------------------------------------- + +.. automodule:: galaxy.webapps.tool_shed.api.repository_revisions + :members: + :undoc-members: + :show-inheritance: + +tools module +---------------------------------------------- + +.. automodule:: galaxy.webapps.tool_shed.api.tools + :members: + :undoc-members: + :show-inheritance: + +users module +---------------------------------------------- + +.. automodule:: galaxy.webapps.tool_shed.api.users + :members: + :undoc-members: + :show-inheritance: + + diff --git a/doc/source/releases/17.09_announce.rst b/doc/source/releases/17.09_announce.rst index 62c63764ecf..bd42499a539 100644 --- a/doc/source/releases/17.09_announce.rst +++ b/doc/source/releases/17.09_announce.rst @@ -42,11 +42,78 @@ To update an existing Galaxy repository run: See `our wiki `__ for additional details regarding the source code locations. +Security +======== + +Together with the 17.09 Galaxy version we release the following three security patches. Per our `Security Policy `__ these has been already applied to all Galaxy releases in the last 12 months. + +If you maintain a publicly accessible Galaxy please consider signing up for this [mailing list](https://lists.galaxyproject.org/listinfo/galaxy-public-servers) to receive the future security patches in advance of the public disclosure. + +Limited Galaxy Data Library unauthorized filesystem access +---------------------------------------------------------- + +Tracked as `GX-2017-0001 `__ + +A medium severity security vulnerability in Galaxy Data Libraries was +recently discovered by Jelle Scholtalbers. This vulnerability allows the following unauthorized actions: + +1. Any user that has been granted the permission to add datasets to a +library, library folder, or to modify an existing library dataset (an +"authorized user"), is able to import any file on the system that is +readable by the user running the Galaxy server. + +2. Anyone can create libraries and library folders (but not add datasets to them) + +The fix for this issue has been applied to Galaxy releases back to 16.07 and can be found in this `commit `__ + +Arbitrary code execution for Galaxy servers with Galaxy Interactive Environments enabled +---------------------------------------------------------------------------------------- + +Tracked as `GX-2017-0002 `__ + +A high severity security vulnerability was recently discovered in Galaxy +Interactive Environments (GIEs) by the Galaxy Committers Team. Anyone with +a Galaxy account can exploit this vulnerability to execute arbitrary code +on the Galaxy server as the user running the Galaxy server process. + +The vulnerability only affects Galaxy servers on which Galaxy Interactive +Environments are enabled (by setting the +`interactive_environment_plugins_directory` +option in galaxy.ini). Because the vulnerability can be exploited to +execute arbitrary code, the impact for affected servers is severe. + +Administrators of Galaxy servers where GIEs *are* enabled should update +immediately. + +The fix for this issue has been applied to Galaxy releases back to 17.05 and can be found in this `commit `__ + +Unauthorized filesystem access via data source tools +---------------------------------------------------- + +Tracked as `GX-2017-0003 `__ + +A medium severity security vulnerability in tools utilizing the Galaxy data +source protocol was recently discovered by the Galaxy Committers Team. This +vulnerability allows anyone able to run an external data source tool to add +to their history any file that is readable by the user running Galaxy jobs +on the host where the job runs. + +Many such "external data source" tools are provided with the Galaxy +distribution and are enabled by default (most tools under the "Get Data" +section of the tool panel), meaning that its exploitability is fairly high, +as only one such tool needs to be enabled to be vulnerable, including any +custom data source tools (any tool that uses +`tools/data_source/data_source.py`). +What files will be readable depends entirely upon what the job's user has +access to read on the host(s) where jobs run. + +The fix for this issue has been applied to Galaxy releases back to 16.07 and can be found in this `commit `__ + Deprecation Notices =================== * The Galaxy Sample Tracking and External Services functionality is now considered deprecated. In future releases we will strip down the related - user interface and introduce configuration option to keep relevant controllers active if desired. `Related PR `__. + user interface and introduce configuration option to keep relevant API controllers active if desired. `Related PR `__. * The deprecated admin-only interface for Galaxy Data Libraries is staged to be removed in the next release. * Workflows API: When exposing WorkflowInvocationSteps ``state`` will no longer be available.