Rails dies again

January 9, 2013


New Severe Rails Vulnerability

All versions of Rails are affected. There are multiple weaknesses in the parameter parsing code for Ruby on Rails which allows attackers to bypass authentication systems, inject arbitrary SQL, inject and execute arbitrary code, or perform a DoS attack on a Rails application.

It is recommended for everyone to upgrade immediately to patched version.

Multiple vulnerabilities in parameter parsing in Action Pack

