CVE-2012-5664: Ruby on Rails: find_by_* SQL Injection
bugzilla.redhat.com
bugzilla.redhat.com
So, to see this you must:
1. Have a Rails App
2. Be using AuthLogic for logins
3. Have let someone access your app's secret key.
This still is a bad bug, but the instances of this bug being used in an attack are going to be very few.