From 401be1d17fb839f68358581c0c74560bd4a24f8f Mon Sep 17 00:00:00 2001 From: Stan Hu Date: Sat, 8 Dec 2018 23:23:39 -0800 Subject: Only allow strings in URL::Sanitizer.valid? Closes https://gitlab.com/gitlab-org/gitlab-ce/issues/55079 --- lib/gitlab/url_sanitizer.rb | 1 + 1 file changed, 1 insertion(+) (limited to 'lib/gitlab/url_sanitizer.rb') diff --git a/lib/gitlab/url_sanitizer.rb b/lib/gitlab/url_sanitizer.rb index 035268bc4f2..880712de5fe 100644 --- a/lib/gitlab/url_sanitizer.rb +++ b/lib/gitlab/url_sanitizer.rb @@ -14,6 +14,7 @@ module Gitlab def self.valid?(url) return false unless url.present? + return false unless url.is_a?(String) uri = Addressable::URI.parse(url.strip) -- cgit v1.2.1