You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There was a lovely blog post on the 12 ways to call a method in Ruby. And it turns out some of these do not get caught by the brakeman scanner and could be abused.
The first example that I found was tap (way # 8 in the reference post):
Kernel.tap(¶ms[:method].to_sym)
The above when called with method=gets will DOS the application and does not currently get caught by brakeman.
There was a lovely blog post on the 12 ways to call a method in Ruby. And it turns out some of these do not get caught by the brakeman scanner and could be abused.
The first example that I found was
tap
(way # 8 in the reference post):The above when called with
method=gets
will DOS the application and does not currently get caught by brakeman.Related issue: #1508
The text was updated successfully, but these errors were encountered: