5 ms·
I strongly recommend loading something like this in your Ruby applications: https://gist.github.com/4507129 https://gist.github.com/4507129 It will prevent YAM
by nelhage 14y ago
I strongly recommend loading something like this in your Ruby applications: https://gist.github.com/4507129 https://gist.github.com/4507129
It will prevent YAML.rb from instantiating arbitrary objects, which will close off this entire class of problems.
Obviously, if you do use YAML as a serialization format for arbitrary objects, this won't work, but odds are you aren't doing that.
- bradleybuda 14y agoUnfortunately, it doesn't look like this patch works in Ruby 1.9, where YAML is actually the Psych module. Any Psych experts know how to make this 1.9-compatible?
- sferik 14y agoYAML is aliased to Psych: irb(main):001:0> require 'yaml' => true irb(main):002:0> YAML => Psych
- thibaut_barrere 14y agoIt doesn't work for me either on 1.9 - anyone with an explanation? I commented here: https://gist.github.com/4507129 https://gist.github.com/4507129
- sferik 14y agoThe patch I applied does not use YAML.tagged_classes.