Advertisement
Promo

Application development Toolkit

Urgent security fix for Ruby on Rails users

Jonathan Bennett

Published: 10 Aug 2006 17:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Ruby on Rails team released a patch on Wednesday, which they describe as "mandatory" for all public sites built using recent versions of the web application framework.

This patch fixes a "serious security concern", the precise nature of which hasn't been revealed, in all versions of Rails from 1.1 up to 1.1.4. "The issue is in fact of such a criticality that we're not going to dig into the specifics", said the team in a statement. However, the flaw does appear to be in the Rails framework, rather than the Ruby language itself.

The team has promised to release more details of the problem in Rails, but says it wants to give users a chance to fix their systems before giving out information that could help attackers. Rails was created by David Heinemeier Hansson, and reached version 1.0 in December of last year.

The updated version of Rails is available through Ruby's Gems package management system, or by downloading the package manually from the Rails Web site.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
34 out of 71 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Discussions

Shibley R Shibley R

Eigg

Sunday 27 December 2009, 1:04 PM

1 comment
Tezzer Tezzer

Nice to see but...

Saturday 26 December 2009, 10:28 AM

5 comments
NoThomas NoThomas

Sure I can

Saturday 26 December 2009, 2:01 AM

11 comments

Win a Creative Zen X-Fi2 player and accessories

Win a Creative Zen X-Fi2 player and accessories

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters