vulnerability
Ruby on Rails Patches Critical Vulnerability
Critical
Summary
A critical vulnerability in Ruby on Rails, specifically related to image processing using the libvips library, has been patched. Attackers could potentially read arbitrary files and expose secrets, leading to remote code execution and lateral movement. The vulnerability affects applications using specific versions of Active Storage and requires updating both Active Storage and libvips to mitigate the risk. As of yet, there's no evidence of active exploitation.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data