Project

General

Profile

Security Vulnerability with Rails prior to 2.3.12

Added by Joshua Villagomez over 13 years ago

Hi All,

Just wondering if there are any plans to upgrade to Rails 2.2.13, due to this recent vulnerability?

http://weblog.rubyonrails.org/2011/6/8/ann-rails-2-3-12-has-been-released
http://www.securityfocus.com/bid/48169/discuss
http://groups.google.com/group/rubyonrails-security/browse_thread/thread/2e516e7acc96c4fb?pli=1

Wondering too any thoughts on applying this patch for those with Redmine 1.2.0? Thanks.