mirror of
https://github.com/rails/rails.git
synced 2022-11-09 12:12:34 -05:00
c4c21a9f8d
url_for supports building polymorphic URLs via an array of arguments (usually symbols and records). If an array is passed, strings can result in unwanted route helper calls. CVE-2021-22885 |
||
---|---|---|
.. | ||
endpoint.rb | ||
inspector.rb | ||
mapper.rb | ||
polymorphic_routes.rb | ||
redirection.rb | ||
route_set.rb | ||
routes_proxy.rb | ||
url_for.rb |