news.mlab.sh
Back to the feed
vulnerability

Ruby on Rails Patches Critical Vulnerability

Critical
Summary

A critical vulnerability in Ruby on Rails, specifically related to image processing using the libvips library, has been patched. Attackers could potentially read arbitrary files and expose secrets, leading to remote code execution and lateral movement. The vulnerability affects applications using specific versions of Active Storage and requires updating both Active Storage and libvips to mitigate the risk. As of yet, there's no evidence of active exploitation.

Read the full article at SecurityWeek

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.