Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
jerf
on April 25, 2017
|
parent
|
context
|
favorite
| on:
Oj – Optimized JSON in Ruby
If you are referring to the Ruby YAML vulnerability, the problem is that the deserializer ends up calling methods on the deserialized object. This says it doesn't, it merely warns you against doing it yourself, or at least doing it carelessly.
Consider applying for YC's Spring batch! Applications are open till Feb 11.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: