Security patch releases to Rails 2.3.x, 3.0.x
weblog.rubyonrails.org
weblog.rubyonrails.org
* There were using Enumerable#reject (ie, default allow) with a strict filter to decide which controllers/actions to route requests to, but case-insensitive filesystems aren't similarly strict.
* (Worst of all) ActiveRecord::QueryMethods#limit/limit_value wasn't sanitized while building queries (try Foo.limit("1,,0") for the flavor).
I don't know what the CSRF thing was either, but it looks like a headachey fix.
Django released a similar fix. According to their changeset, we'll see a release from them shortly as well. Maybe they'll shed some more light on the issue.
I don't know yet when the full full disclosure will happen; I just know that right now I'm really not at liberty to do that.
Flash and Java both disallow cross-domain requests unless specifically allowed by a crossdomain.xml file (or you use a DNS rebinding attack on Java). Furthermore, to the best of my knowledge, if you can make an HTTP request in Java or Flash you can read back the result.
Resetting sessions on CSRF failures is going to suck for us.
In my tweet, I just meant to say that Rails checked for something very simple: a header that Flash's addRequestHeader() can trivially fake out. As Neal points out, that can't be the whole story — but I suspect it's part of it.
Briefly, when both frameworks got an "X-Requested-With" header, they assumed that it was coming from a browser XmlHttpRequest, and that the same-origin policy was in effect. So, they skipped CSRF checks.
However, it turns out that there is a way (details still not disclosed, other than that plugins and redirects are involved) for an attacker to force arbitrary headers onto a web request. Ooops.
Both frameworks are now applying CSRF checks strictly, with no exceptions for apparent XHR.
http://groups.google.com/group/rubyonrails-security/browse_t...
EDIT: If you run bundle update with no parameters, bundler will ignore any previously installed gems and resolve all dependencies again based on the latest versions of all gems available in the sources.