fix YAML safe load capatibility potential error#3231
fix YAML safe load capatibility potential error#3231pengyin-shan merged 4 commits intodevelopmentfrom
Conversation
briri
left a comment
There was a problem hiding this comment.
Looks good @pengyin-shan
What do you mean by "when moving the 'Download' tab"? I haven't seen any issues with this in DMPTool Rails 6.1.
So this occurred for some user groups (so far DMP Assisant has only seen one user has this problem). I meant to use click 'Download' tab. i.e. User tried to download the plan, but the error message will show and bring the user back to their dashboard |
As an update, I moved separate settings from the configuration file to |
Fixes a possible error caused by a bug in Rails. Some users see this error when moving the 'Download' tab:

Rails proposed the solution: https://discuss.rubyonrails.org/t/cve-2022-32224-possible-rce-escalation-bug-with-serialized-columns-in-active-record/81017
Thus, made the following changes:
Symbol.HashwithDifferentAccess,DateandTimeare also trusted and should be added)Gemfile.lockgot updated with the arm64 version there