LWN.net Logo

Github compromised

Github compromised

Posted Mar 5, 2012 12:42 UTC (Mon) by Gollum (subscriber, #25237)
Parent article: Github compromised

The vulnerability in question is a nice one, taking advantage of the RoR Mass Assignment operator to allow overwriting of records which should not normally be exposed.

All RoR apps should check whether they are vulnerable to this.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds