lib/brakeman/checks/check_yaml_parsing.rb in brakeman-4.3.1 vs lib/brakeman/checks/check_yaml_parsing.rb in brakeman-4.4.0
- old
+ new
@@ -20,10 +20,10 @@
"3.1.10"
elsif version_between? "3.2.0", "3.2.10"
"3.2.11"
end
- message = "Rails #{rails_version} has a remote code execution vulnerability: upgrade to #{new_version} or disable XML parsing"
+ message = msg(msg_version(rails_version), " has a remote code execution vulnerability. Upgrade to ", msg_version(new_version), " or disable XML parsing")
warn :warning_type => "Remote Code Execution",
:warning_code => :CVE_2013_0156,
:message => message,
:confidence => :high,