Rails form helper security vulnerability
A vulnerability has been found in the Rails form helpers that allows an attacker to inject arbitrary HTML into pages. This opens up an unpatched Rails app to potential cross site scripting attacks (XSS), which could result in stolen session cookies and other such scenarios.
All versions of Rails above and including version 2.0 are affected. There are two new official releases to fix this, 2.3.4 and 2.2.3. If you’re still running Rails 2.0 or 2.1 and can’t upgrade, patches have been provided by the security team but need applying manually. In this case, we’d recommend vendoring the rails gems and then applying the patches.
More details from the security team here.
Images:
- Technology:
- Add new comment
- 122 reads
- Feed: brightbox
- Original article


Recent comments
1 year 23 weeks ago
1 year 23 weeks ago
1 year 25 weeks ago
1 year 27 weeks ago
1 year 42 weeks ago
1 year 45 weeks ago
1 year 45 weeks ago
1 year 45 weeks ago
1 year 46 weeks ago
1 year 48 weeks ago