Version: 2008
  • On MovieTome: The 10 worst movies of 2009 so far!

August 10, 2006 10:45 AM PDT

Rails users urged to fix flaw immediately

  • Post a comment
Users of Ruby on Rails have been told to update their installations immediately, following the discovery of a security flaw in the popular open-source Web application framework.

The Ruby on Rails team members released a patch on Wednesday that they describe as "mandatory" for all public sites built using recent versions of the Web-application framework.

This patch fixes what the team called a "serious security concern," the precise nature of which hasn't been revealed, in all versions of Rails from 1.1 up to 1.1.4.

"The issue is in fact of such a criticality that we're not going to dig into the specifics," the team said in a statement. However, the flaw does appear to be in the Rails framework rather than in the Ruby language itself.

The team has promised to release more details of the problem in Rails, but said it wants to give users a chance to fix their systems before giving out information that could help attackers. Rails was created by David Heinemeier Hansson and reached version 1.0 in December of last year.

The updated version of Rails is available through Ruby's Gems package management system, or by downloading the package manually from the Rails Web site.

Jonathan Bennett of Builder UK reported from London.

See more CNET content tagged:
Ruby on Rails, framework, flaw, Web application, security

advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (0.72%) 73.00 10,270.47
S&P 500 (0.57%) 6.24 1,093.48
NASDAQ (0.88%) 18.86 2,167.88
CNET TECH (0.63%) 9.86 1,587.17
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right