File: cve_2020_10663_spec.rb

package info (click to toggle)
ruby3.4 3.4.5-1~exp1
  • links: PTS, VCS
  • area: main
  • in suites: experimental
  • size: 154,784 kB
  • sloc: ruby: 1,259,653; ansic: 829,955; yacc: 28,233; pascal: 7,359; sh: 3,864; python: 1,799; cpp: 1,158; asm: 808; makefile: 801; javascript: 414; lisp: 109; perl: 62; awk: 36; sed: 4; xml: 4
file content (46 lines) | stat: -rw-r--r-- 1,236 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
require_relative '../spec_helper'
require 'json'

module JSONSpecs
  class MyClass
    def initialize(foo)
      @foo = foo
    end

    def self.json_create(hash)
      new(*hash['args'])
    end

    def to_json(*args)
      { 'json_class' => self.class.name, 'args' => [ @foo ] }.to_json(*args)
    end
  end
end

guard -> {
  JSON.const_defined?(:Pure) or
  version_is(JSON::VERSION, '2.3.0')
} do
  describe "CVE-2020-10663 is resisted by" do
    it "only creating custom objects if passed create_additions: true or using JSON.load" do
      obj = JSONSpecs::MyClass.new("bar")
      JSONSpecs::MyClass.should.json_creatable?
      json = JSON.dump(obj)

      JSON.parse(json, create_additions: true).class.should == JSONSpecs::MyClass
      JSON(json, create_additions: true).class.should == JSONSpecs::MyClass
      if version_is(JSON::VERSION, '2.8.0')
        warning = /\Wcreate_additions:\s*true\W\s+is\s+deprecated/
      else
        warning = ''
      end
      -> {
        JSON.load(json).class.should == JSONSpecs::MyClass
      }.should output_to_fd(warning, STDERR)

      JSON.parse(json).class.should == Hash
      JSON.parse(json, nil).class.should == Hash
      JSON(json).class.should == Hash
    end
  end
end