Skip to content

Conversation

@lcreid
Copy link
Contributor

@lcreid lcreid commented Jul 17, 2022

https://discuss.rubyonrails.org/t/cve-2022-32224-possible-rce-escalation-bug-with-serialized-columns-in-active-record/81017 prevents serialization of a Symbol because it's potentially a security vulnerability. This PR changes a test so it serializes and attribute value with a String key rather than a Symbol.

@lcreid lcreid requested review from donv and thimo July 17, 2022 21:16
@lcreid lcreid force-pushed the fix-test-for-cve branch from 4de9d54 to 812c7d0 Compare July 17, 2022 21:18
@lcreid lcreid force-pushed the fix-test-for-cve branch from 812c7d0 to b26fb07 Compare July 17, 2022 21:19
@donv donv merged commit 979474f into bootstrap-ruby:main Jul 20, 2022
@lcreid lcreid deleted the fix-test-for-cve branch October 1, 2022 20:48
@donv donv mentioned this pull request May 19, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants