I'm curious about the technical details of the CSRF bypass vulnerability. Anyone know what the "combinations of browser plugins and HTTP redirects" that lead to it are?
http://groups.google.com/group/rubyonrails-security/browse_t...
http://groups.google.com/group/rubyonrails-security/browse_t...