rpaul80/railsgoat

Dangerous Function Deserialization Security Finding

Opened this issue · 0 comments

A potential security finding was discovered by the Dangerous Function Deserialization Boost Security rule.

Rule Description
description: dangerous-function-deserialization

Finding Location

user = Marshal.load(Base64.decode64(params[:user])) unless params[:user].nil?

Action to Fix
To fix this security finding check out the Boost documentation for more information and remediation steps.
If this is not a valid finding, then add a comment to the line of code of the finding with the word noboost in it and commit it.


This ticket was created by Boost Security. Do not delete below this line
Boost Id: 8276e315-3b48-43f0-9023-0fa5c0457033