Some recently disclosed vulnerabilities rails developers should be aware of:
- Denial of Service Vulnerability in Action View - https://seclists.org/oss-sec/2019/q1/177
- File Content Disclosure in Action View - https://seclists.org/oss-sec/2019/q1/178
- Possible Remote Code Execution Exploit in Rails Development Mode - https://seclists.org/oss-sec/2019/q1/176
Upgrade your apps.
An example of the File Content Disclosure one:
https://twitter.com/iblueconnection/status/1107702203349979136
#security #netsec #appsec