Ruby on Rails security updates address SQL injection flaw
- 03 January, 2013 14:12
- Comments
The developers of Ruby on Rails, a popular Web application development framework for the Ruby programming language, released versions 3.2.10, 3.1.9, and 3.0.18 of the software on Wednesday in order to patch a serious SQL injection vulnerability.
"These releases contain an important security fix," the Rails development team said in a blog post. "It is recommended that all users upgrade immediately."
The vulnerability is located in the framework's Active Record database query interface and allows potential attackers to inject arbitrary SQL (Structured Query Language) statements.
SQL injection vulnerabilities are commonly exploited by attackers to extract information from databases.
The Rails developers apologized for releasing a security update so close to the holidays, but said that they were forced to rush out a patch because the vulnerability had been publicly disclosed.
In order to help users who can't immediately upgrade to the latest versions of the framework, the Rails development team published a workaround and released manual patches that can be easily applied to older versions, including two that are no longer supported.
That said, users of unsupported versions were urged to upgrade as soon as possible because the future availability of security fixes for those versions is not guaranteed. Only Rails 3.1.x and 3.2.x series are supported at the moment, the developers said.
- Bookmark this page
- Share this article
- Got more on this story? Email TechWorld
- Follow TechWorld on twitter
-
WikiLeaks Party closer to registering
-
Philip's 'smart' lightbulbs hit Australia
-
Philip's 'smart' lightbulbs hit Australia
-
Australia lags Mongolia in Internet speeds
-
Salesforce.com to buy Clipboard, shutting down service












Recent comments
10 hours, 4 minutes ago
1 day, 13 hours ago
1 day, 16 hours ago
6 days, 15 hours ago
1 week, 1 day ago
1 week, 1 day ago
1 week, 4 days ago
1 week, 5 days ago
1 week, 5 days ago
1 week, 5 days ago