Actions
Patch #37452
closedUpdate Rails to 6.1.7
Description
Rails team released new versions of rails that fixes CVE-2022-32224 security issue (https://discuss.rubyonrails.org/t/cve-2022-32224-possible-rce-escalation-bug-with-serialized-columns-in-active-record/81017). Updated version is not backward compatible, application should explicitly enable permitted classes for YAML serialization:
config.active_record.yaml_column_permitted_classes: [Symbol]
Files
Related issues
Actions