Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Ruby on Rails patches more critical vulnerabilities

Second time this month that Ruby on Rails has released updated versions for serious software flaws

Article comments

Those using the Ruby on Rails web application framework on their websites are being advised to update the software immediately after multiple new vulnerabilities were found. It's the second time this month that Rails has been patched because of serious flaws.

Ruby on Rails is an open-source web application development framework that is widely used across the Internet on websites including Hulu, GroupOn and Scribd.

One of the problems, CVE-2013-0156, lies in the parameter parsing code for Ruby on Rails, which would allow attackers to bypass authentication systems, perform SQL injection attacks or a denial of service attack against applications using Rails, according to an advisory on Tuesday. A SQL injection attack involves sending commands through a web-based form to a website's backend database, which, if not protected properly, can return sensitive data.

The second issue, CVE-2013-0155, would allow an attacker to send unexpected database queries with the command "IS NULL" due to the way Active Record interprets parameters in combination with the way that JSON parameters are parsed, according to another writeup.

The writeup advised that this particular vulnerability is a variant of CVE-2012-2660 and CVE-2012-2694. "Even if you upgraded to address those issues, you must take action again," it said.

Four updated versions of Rails were released on Tuesday: 3.2.11, 3.1.10, 3.0.19, and 2.3.15, according to the Rails blog. "These releases contain two extremely critical security fixes so please update immediately," it advised.

It's the second time this month that Rails has been updated due to critical vulnerabilities. Rails versions 3.2.10, 3.1.9, and 3.0.18 were released on Jan. 2 to address CVE-2012-5664, a SQL injection vulnerability.

Rails apologised for releasing that patch so close to the holiday break, but said that "regrettably the exploit has already been publicly disclosed, and we don't feel we can delay the release."



Share:

More from Techworld

More relevant IT news

Comments



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *