Attack wave on Ruby on Rails (The H)
[Posted May 29, 2013 by ris]
The H
reports
increasing attempts to compromise servers via a security hole in Ruby
on Rails. "
On his blog, security expert Jeff Jarmoc reports
that the criminals are trying to exploit one of the vulnerabilities
described by CVE identifier 2013-0156. Although the holes were closed
back in January, more than enough servers on the net are probably still
running an obsolete version of Ruby." The current versions of Ruby on Rails are 3.2.13, 3.1.12 and 2.3.18.
(
Log in to post comments)