升级Rails至6.1.7遇Psych::DisallowedClass问题,如何规避yaml_unsafe_load?
升级Rails 6.1.7时遇到Active Record序列化列安全问题及解决方案咨询
问题背景
把Rails应用升级到6.1.7版本后,碰到了Active Record序列化列相关的安全限制问题,导致大量测试用例失败。这个问题和序列化列存在的RCE升级安全漏洞有关。
测试失败示例
以下是触发测试失败的步骤代码:
Given('that there are {int} past events') do |number| number.times do create(:event_instance, category: 'Scrum', created_at: rand(1.months.seconds.to_i).seconds.ago, project_id: nil) end end
另一个失败场景的报错信息:
Given I have some videos on project “hello world” # features/step_definitions/youtube_steps.rb:33
Tried to load unspecified class: ActiveSupport::HashWithIndifferentAccess (Psych::DisallowedClass)
internal:kernel:90:intap’ ./features/step_definitions/youtube_steps.rb:44:inblock (2 levels) in'
./features/step_definitions/youtube_steps.rb:43:intimes’ ./features/step_definitions/youtube_steps.rb:43:in/^the project “(.?)” has (\d+) videos of user “(.?)“$/'
./features/step_definitions/youtube_steps.rb:34:in/^I have some videos on project “(.*?)“$/' features/users/user_videos.feature:33:inI have some videos on project “hello world”'
当前临时配置方案
查资料知道可以用config.active_record.use_yaml_unsafe_load临时绕开,但实际测试里只有配置以下内容才能让测试通过:
config.active_record.yaml_column_permitted_classes = [ Symbol, ActiveSupport::HashWithIndifferentAccess, ActionController::Parameters ]
想咨询的问题
- 上面这个
yaml_column_permitted_classes配置存在哪些安全风险或者潜在问题? - 有没有不依赖临时方案的根本解决办法?
内容的提问来源于stack exchange,提问作者mrlindsey
相关产品推荐
相关产品推荐

