From 65831f4d3e6067b58a8b53e2c12d85a0dfe18647 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?R=C3=A9gis=20Hanol?= Date: Wed, 15 Jan 2020 22:05:38 +0100 Subject: [PATCH] SECURITY: use strict JSON parsing when parsing backup metadata --- lib/backup_restore/restorer.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/backup_restore/restorer.rb b/lib/backup_restore/restorer.rb index a5ea6a03163..cfa691b04e7 100644 --- a/lib/backup_restore/restorer.rb +++ b/lib/backup_restore/restorer.rb @@ -220,7 +220,7 @@ module BackupRestore ) end - data = Oj.load_file(@meta_filename) + data = JSON.parse File.read(@meta_filename) raise "Failed to load metadata file." if !data data else