Security Advisories (2)
CVE-2012-5572 (2014-05-30)

CRLF injection vulnerability in the cookie method allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name.

CVE-2011-1589 (2011-04-05)

Directory traversal vulnerability (Mojolicious report, but Dancer was vulnerable as well).

NAME

Dancer::Serializer::Mutable - (De)Serialize content using the appropriate HTTP header

SYNOPSIS

DESCRIPTION

This serializer will try find the best (de)serializer for a given request. For this, it will go through:

  • The content_type from the request headers

  • the content_type parameter from the URL

  • the accept from the request headers

  • The default is application/json

METHODS

serialize

Serialize a data structure to a YAML structure.

deserialize

Deserialize a YAML structure to a data structure

content_type

Return 'application/json'