[ANN] Rails 3.1.8 has been released!!!

6 views
Skip to first unread message

Santiago Pastorino

unread,
Aug 9, 2012, 5:36:14 PM8/9/12
to rubyonra...@googlegroups.com, rubyonra...@googlegroups.com, ruby...@ruby-lang.org
Good news everyone! Rails version 3.1.8 has been released.

This release of Rails contains three important security fixes:

* [CVE-2012-3463 Ruby on Rails Potential XSS Vulnerability in
select_tag prompt](https://groups.google.com/d/msg/rubyonrails-security/fV3QUToSMSw/eHBSFOUYHpYJ)
* [CVE-2012-3464 Potential XSS Vulnerability in Ruby on
Rails](https://groups.google.com/d/msg/rubyonrails-security/kKGNeMrnmiY/r2yM7xy-G48J)
* [CVE-2012-3465 XSS Vulnerability in
strip_tags](https://groups.google.com/d/msg/rubyonrails-security/FgVEtBajcTY/tYLS1JJTu38J)

All changes can be found on
[github](https://github.com/rails/rails/compare/v3.1.7...v3.1.8).

Thanks everyone!

--

Santiago Pastorino
WyeWorks Co-founder
http://www.wyeworks.com

Twitter: http://twitter.com/spastorino
Github: http://github.com/spastorino
Reply all
Reply to author
Forward
0 new messages