Release date:
Updated on: 2013-01-10
Affected Systems:
Ruby on Rails <3.2.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57187
CVE (CAN) ID: CVE-2013-0156
Ruby on Rails (RoR or Rails) is an open-source Web application framework written in Ruby. It is developed in strict accordance with the MVC structure.
Multiple security vulnerabilities such as security Permission Bypass, SQL injection, denial of service, and code execution exist in Ruby on Rails, attackers can exploit these vulnerabilities to bypass certain security restrictions, execute arbitrary code in affected applications, perform unauthorized database operations, and deny service to legal users.
<* Source: Ben Murphy
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ruby on Rails
-------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.rubyonrails.com/