lib/brakeman/checks/check_yaml_parsing.rb in brakeman-1.9.1 vs lib/brakeman/checks/check_yaml_parsing.rb in brakeman-1.9.2
- old
+ new
@@ -36,9 +36,10 @@
message = "Parsing YAML request parameters enables remote code execution: disable YAML parser"
warn :warning_type => "Remote Code Execution",
:message => message,
:confidence => CONFIDENCE[:high],
+ :file => gemfile_or_environment,
:link_path => "https://groups.google.com/d/topic/rubyonrails-security/61bkgvnSGTQ/discussion"
end
end
def disabled_xml_parser?