Release date:
Updated on:
Affected Systems:
Ruby on Rails 3.x
Ruby on Rails 2.x
Ruby on Rails 1.x
Unaffected system:
Ruby on Rails 3.0.4
Ruby on Rails 2.3.11
Description:
--------------------------------------------------------------------------------
Bugtraq id: 46291
Cve id: CVE-2011-0446, CVE-2011-0447
Ruby on Rails (RoR or Rails) is an open-source Web application framework written in Ruby. It is developed in strict accordance with the MVC structure.
The implementation of Ruby on Rails has the cross-site scripting and Cross-Site Request Forgery vulnerabilities. Attackers can exploit the cross-site scripting vulnerability to execute arbitrary script code in the affected browsers and steal Cookie authentication creden.
<* Source: Brendan Coles
Rick Olson
Github
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ruby on Rails
-------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.rubyonrails.com/