LWN: Comments on "Two new (one "critical") Ruby on Rails vulnerabilities" https://lwn.net/Articles/532053/ This is a special feed containing comments posted to the individual LWN article titled "Two new (one "critical") Ruby on Rails vulnerabilities". en-us Fri, 03 Oct 2025 18:50:00 +0000 Fri, 03 Oct 2025 18:50:00 +0000 https://www.rssboard.org/rss-specification lwn@lwn.net ETOOMANY0DAYS https://lwn.net/Articles/533184/ https://lwn.net/Articles/533184/ meuh <div class="FormattedComment"> Hopefully there's JRuby on Rails ... hopping that two 0days cancel each other ...<br> <p> <a href="https://github.com/jruby/jruby/wiki/JRubyOnRails">https://github.com/jruby/jruby/wiki/JRubyOnRails</a><br> <p> <p> </div> Fri, 18 Jan 2013 14:18:42 +0000 Two new (one "critical") Ruby on Rails vulnerabilities https://lwn.net/Articles/532291/ https://lwn.net/Articles/532291/ jake <div class="FormattedComment"> <font class="QuotedText">&gt; Why the scare quotes around "critical?"</font><br> <p> they weren't meant as scare quotes, just regular quotes. sorry for the confusion.<br> <p> jake<br> </div> Thu, 10 Jan 2013 16:07:08 +0000 Two new (one "critical") Ruby on Rails vulnerabilities https://lwn.net/Articles/532248/ https://lwn.net/Articles/532248/ quad <div class="FormattedComment"> Why the scare quotes around "critical?"<br> </div> Thu, 10 Jan 2013 14:28:08 +0000 Two new (one "critical") Ruby on Rails vulnerabilities https://lwn.net/Articles/532224/ https://lwn.net/Articles/532224/ ovitters <div class="FormattedComment"> Dutch government requires DigiD if a citizen wants to login to a government website (any). DigiD apparently uses Ruby on Rails, so they took the entire DigiD offline. As a result, you could not login anymore. Meaning: you could not handle anything government related issue electronically. Whoops :P<br> <p> One of the various Dutch articles about this:<br> <a href="http://nos.nl/artikel/459883-digid-onbereikbaar-na-lek.html">http://nos.nl/artikel/459883-digid-onbereikbaar-na-lek.html</a><br> </div> Thu, 10 Jan 2013 10:32:14 +0000 Two new (one "critical") Ruby on Rails vulnerabilities https://lwn.net/Articles/532199/ https://lwn.net/Articles/532199/ bronson <div class="FormattedComment"> It appears that Rails's desire to accept any input and the assumption "user input can never be a symbol" are in ongoing conflict.<br> <p> Likely both are wrong. Nobody accepts parameters as XML or YAML so why do these code paths exist at all?<br> <p> I really hope they clean up the root problem in Rails 4. All this patching is getting tiresome.<br> </div> Thu, 10 Jan 2013 02:36:58 +0000 Two new (one "critical") Ruby on Rails vulnerabilities https://lwn.net/Articles/532054/ https://lwn.net/Articles/532054/ dakas Ruby on Rails continues keeping <a rel="nofollow" href="http://xkcd.com/327/">the xkcd comic "Exploits of a mom"</a> topical. Wed, 09 Jan 2013 14:19:58 +0000