<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<rss version="2.0">
  <channel>
  <title>Ruby on Rails: Security Google Group</title>
  <link>http://groups.google.com/group/rubyonrails-security</link>
  <description>Security annoucements for Ruby on Rails.</description>
  <language>en</language>
  <item>
  <title>Ruby on Rails 1.2.6</title>
  <link>http://groups.google.com/group/rubyonrails-security/browse_thread/thread/1bea46abaebb2998/82eb2bccfafe4948?show_docid=82eb2bccfafe4948</link>
  <description>
  The rails core team has released ruby on rails 1.2.6 to address a bug &lt;br&gt; in the fix for session fixation attacks(CVE-2007-5380). The CVE &lt;br&gt; Identifier for this new issue is CVE-2007-6077. &lt;br&gt; You should upgrade to this new release if you do not take specific &lt;br&gt; session-fixation counter measures in your application. 1.2.6 also
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/rubyonrails-security/browse_thread/thread/1bea46abaebb2998/82eb2bccfafe4948?show_docid=82eb2bccfafe4948</guid>
  <author>
  mich...@koziarski.com
  (Michael Koziarski)
  </author>
  <pubDate>Sat, 24 Nov 2007 22:16:29 UT
</pubDate>
  </item>
  <item>
  <title>Ruby on Rails 1.2.5</title>
  <link>http://groups.google.com/group/rubyonrails-security/browse_thread/thread/034c7766ca4d5505/73a2f473a483b866?show_docid=73a2f473a483b866</link>
  <description>
  The rails core team has released ruby on rails 1.2.5 to address a &lt;br&gt; potential XSS exploit with our json serialization. The CVE Identifier &lt;br&gt; for this problem is CVE-2007-3227. &lt;br&gt; You are only at risk if you embed the result of a .to_json call in a &lt;br&gt; page you generate. For example: &lt;br&gt; &amp;lt;script type=&amp;quot;text/javascript&amp;quot;&amp;gt;
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/rubyonrails-security/browse_thread/thread/034c7766ca4d5505/73a2f473a483b866?show_docid=73a2f473a483b866</guid>
  <author>
  mich...@koziarski.com
  (Michael Koziarski)
  </author>
  <pubDate>Fri, 12 Oct 2007 22:30:23 UT
</pubDate>
  </item>
  <item>
  <title>Re: Ruby on Rails 1.2.4</title>
  <link>http://groups.google.com/group/rubyonrails-security/browse_thread/thread/239b034f4f808834/e3473b373afff5a0?show_docid=e3473b373afff5a0</link>
  <description>
  The issues mentioned in this advisory now have CVE numbers. &lt;br&gt; CVE-2007-5379 &lt;br&gt; CVE-2007-5380 &lt;br&gt; This was a typo, to re-enable URL based sessions you need the &lt;br&gt; following line in your environment.rb file. &lt;br&gt; config.action_controller.sessi on_options[:cookie_only] = false
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/rubyonrails-security/browse_thread/thread/239b034f4f808834/e3473b373afff5a0?show_docid=e3473b373afff5a0</guid>
  <author>
  mich...@koziarski.com
  (Michael Koziarski)
  </author>
  <pubDate>Fri, 12 Oct 2007 22:25:00 UT
</pubDate>
  </item>
  <item>
  <title>Rails 1.2.5: Closes JSON XSS vulnerability</title>
  <link>http://groups.google.com/group/rubyonrails-security/browse_thread/thread/225dcc61aaefad42/4b6c62c789ad64f2?show_docid=4b6c62c789ad64f2</link>
  <description>
  This release closes a JSON XSS vulnerability, fixes a couple of minor &lt;br&gt; regressions introduced in 1.2.4, and backports a handful of features &lt;br&gt; and fixes from the 2.0 preview release. &lt;br&gt; All users of Rails 1.2.4 or earlier are advised to upgrade to 1.2.5, &lt;br&gt; though it isn&#39;t strictly necessary if you aren&#39;t working with JSON.
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/rubyonrails-security/browse_thread/thread/225dcc61aaefad42/4b6c62c789ad64f2?show_docid=4b6c62c789ad64f2</guid>
  <author>
  david.heineme...@gmail.com
  (DHH)
  </author>
  <pubDate>Fri, 12 Oct 2007 16:50:53 UT
</pubDate>
  </item>
  <item>
  <title>Ruby on Rails 1.2.4</title>
  <link>http://groups.google.com/group/rubyonrails-security/browse_thread/thread/239b034f4f808834/439c36b0eee81b47?show_docid=439c36b0eee81b47</link>
  <description>
  The release of Ruby on Rails 1.2.4 addresses some potential security &lt;br&gt; issues, all users of earlier versions are advised to upgrade to 1.2.4: &lt;br&gt; The particular issues are: &lt;br&gt; Maliciously crafted requests to a rails application could cause the &lt;br&gt; XML parser to read files from the server&#39;s disk or the network. 1.2.4
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/rubyonrails-security/browse_thread/thread/239b034f4f808834/439c36b0eee81b47?show_docid=439c36b0eee81b47</guid>
  <author>
  mich...@koziarski.com
  (Michael Koziarski)
  </author>
  <pubDate>Wed, 10 Oct 2007 01:33:45 UT
</pubDate>
  </item>
  </channel>
</rss>
