Insecure Processing of Data
This category covers the following issues:
Why is this important?
Serialization is the process of translating data structures storable formats. In Ruby, objects can be serialized into strings and vice-versa, strings can be deserialized into objects. This functionality can be accessed with methods related to YAML, JSON, CSV, and Marshalling. Insecure deserialization describes the processing of malicious data which in term allows hackers to execute arbitrary code in the context of your application. These issues are common and have been the cause of many high profile breaches.
Fixing Insecure Deserialization
Option A: Use SafeYAML
- Go through the issues that GuardRails identified in the PR.
safe_yamlby adding this line to your
This would work by default prevent most of the attack vectors against YAML without requiring changing the existing
- There is more configuration available for this gem.
- Test it
- Ship it 🚢 and relax 🌴