lib/brakeman/checks/check_model_serialize.rb in brakeman-min-4.3.1 vs lib/brakeman/checks/check_model_serialize.rb in brakeman-min-4.4.0
- old
+ new
@@ -55,10 +55,10 @@
end
warn :model => model.name,
:warning_type => "Remote Code Execution",
:warning_code => :CVE_2013_0277,
- :message => "Serialized attributes are vulnerable in Rails #{rails_version}, upgrade to #{@upgrade_version} or patch.",
+ :message => msg("Serialized attributes are vulnerable in ", msg_version(rails_version), ", upgrade to ", msg_version(@upgrade_version), " or patch"),
:confidence => confidence,
:link => "https://groups.google.com/d/topic/rubyonrails-security/KtmwSbEpzrU/discussion",
:file => model.file,
:line => model.top_line
end