[Rails] Re: Rails exploit in multi_xml remote code execution monkeypatch
After I sobered up, it's actually just anything that ends up using multi_xml.
Sorry for any confusion. :/
~Spaceghost
On Thursday, January 10, 2013 7:28:12 PM UTC-5, Spaceghost wrote:
Our friend the fowlest of ducks put together a nice monkeypatch for us to require after multi_xml is required.This affects any rails project, any project using activesupport, possibly more.https://gist.github.com/d7f6d9f4925f413621aa You probably won't need help with applying it, but here's an update on a proper fix. Should be in by Saturday perhaps.I'm also going to take this chance to be that guy and say retweet this if you can. https://twitter.com/fowlduck/status/ 289514566558310401 ~Spaceghost
You received this message because you are subscribed to the Google Groups "Ruby on Rails: Talk" group.
To post to this group, send email to rubyonrails-talk@googlegroups.com.
To unsubscribe from this group, send email to rubyonrails-talk+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msg/rubyonrails-talk/-/7IK5XMOsxx8J.
For more options, visit https://groups.google.com/groups/opt_out.
0 Comments:
Post a Comment
Subscribe to Post Comments [Atom]
<< Home