Rails 5.0.0.beta2 等多個版本發布,
Rails 5.0.0.beta1.1, 4.2.5.1, 4.1.14.1, 3.2.22.1, and rails-html-sanitizer 1.0.3 發布,有重要安全修復,請盡快更新:
-
CVE-2015-7576 Timing attack vulnerability in basic authentication in Action Controller.
-
CVE-2016-0751 Possible Object Leak and Denial of Service attack in Action Pack
-
CVE-2015-7577 Nested attributes rejection proc bypass in Active Record.
-
CVE-2016-0752 Possible Information Leak Vulnerability in Action View
-
CVE-2016-0753 Possible Input Validation Circumvention in Active Model
-
CVE-2015-7581 Object leak vulnerability for wildcard controller routes in Action Pack
更多內容:
來自: http://www.oschina.net//news/70210/rails-5-0-0-beta2
本文由用戶 jopen 自行上傳分享,僅供網友學習交流。所有權歸原作者,若您的權利被侵害,請聯系管理員。
轉載本站原創文章,請注明出處,并保留原始鏈接、圖片水印。
本站是一個以用戶分享為主的開源技術平臺,歡迎各類分享!