Rails team has been released version 3.2.6. It contains major security fixes.
CVE-2012-2694 Ruby on Rails Unsafe Query Generation Risk in Ruby on Rails
CVE-2012-2695 Ruby on Rails SQL Injection
Source code and more information available here
Reference:
http://weblog.rubyonrails.org/2012/6/12/ann-rails-3-2-6-has-been-released/
No comments:
Post a Comment