Class: Brakeman::CheckNestedAttributes
- Inherits:
-
BaseCheck
- Object
- BaseCheck
- Brakeman::CheckNestedAttributes
- Defined in:
- lib/brakeman/checks/check_nested_attributes.rb
Overview
Check for vulnerability in nested attributes in Rails 2.3.9 and 3.0.0 http://groups.google.com/group/rubyonrails-security/browse_thread/thread/f9f913d328dafe0c
Instance Method Summary collapse
Instance Method Details
#run_check ⇒ Object
10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 |
# File 'lib/brakeman/checks/check_nested_attributes.rb', line 10 def run_check version = rails_version if (version == "2.3.9" or version == "3.0.0") and uses_nested_attributes? = msg("Vulnerability in nested attributes ", msg_cve("CVE-2010-3933"), ". Upgrade to ") if version == "2.3.9" << msg_version("2.3.10") else << msg_version("3.0.1") end warn :warning_type => "Nested Attributes", :warning_code => :CVE_2010_3933, :message => , :confidence => :high, :gem_info => gemfile_or_environment, :link_path => "https://groups.google.com/d/topic/rubyonrails-security/-fkT0yja_gw/discussion", :cwe_id => [20] end end |
#uses_nested_attributes? ⇒ Boolean
32 33 34 35 36 37 38 |
# File 'lib/brakeman/checks/check_nested_attributes.rb', line 32 def uses_nested_attributes? active_record_models.each do |_name, model| return true if model.[:accepts_nested_attributes_for] end false end |