Unsafe Query Generation Risk in Ruby on Rails (CVE-2013-0155)
groups.google.com
groups.google.com
Is there a site I can sign up for package update notifications for a bunch of projects?
I don't want info on all CVEs or all system packages but just a list of packages I'm interested in (and more than just ubuntu/Debian packages).
I seem to remember one site on HN but my google-fu is weak tonight...
By the way, what do freelancers on HN feel about general responsibility for security maintenance after the work has been done?
My understanding is that as long as there is a JSON endpoint accepting parameters, and the parameters are used for query generation without going through a proper validation layer [1], then the app is vulnerable.
[1] In python, this would be things like FormEncode, WTForms, Colander, etc.