On mySimon: Robert Rodriguez Studded-Band Skirt
BNET Business Network:
BNET
TechRepublic
ZDNet

By Jonathan Bennett
Posted on ZDNet News: Aug 10, 2006 5:45:00 PM

Users of Ruby on Rails have been told to update their installations immediately, following the discovery of a security flaw in the popular open-source Web application framework.

The Ruby on Rails team members released a patch on Wednesday that they describe as "mandatory" for all public sites built using recent versions of the Web-application framework.

This patch fixes what the team called a "serious security concern," the precise nature of which hasn't been revealed, in all versions of Rails from 1.1 up to 1.1.4.

"The issue is in fact of such a criticality that we're not going to dig into the specifics," the team said in a statement. However, the flaw does appear to be in the Rails framework rather than in the Ruby language itself.

The team has promised to release more details of the problem in Rails, but said it wants to give users a chance to fix their systems before giving out information that could help attackers. Rails was created by David Heinemeier Hansson and reached version 1.0 in December of last year.

The updated version of Rails is available through Ruby's Gems package management system, or by downloading the package manually from the Rails Web site.

Jonathan Bennett of Builder UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 5 Talkback(s)
No Scrutiny on ROR
RoR is the latest much hyped vaporware. It is supposed to cure all the ills of Web Development and more. This much hyped framework seems to be unravelling now.... (Read the rest)
Posted by: xyz10_z Posted on: 08/11/06 You are currently: a Guest | | Terms of Use
youwch....  JoeMama_z | 08/10/06
Hackers can just reverse engineer the changes  PB_z | 08/10/06
does keep the script kiddies from doing damage though...  Monkey_MCSE | 08/10/06
Situation normal  TonyMcS | 08/10/06
No Scrutiny on ROR  xyz10_z | 08/11/06

What do you think?

advertisement
Click Here
advertisement

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and