Heroku sending out e-mails to all app owners regarding rails vulnerability
blog.heroku.com
blog.heroku.com
However if any of those apps are vulnerable doesn't it mean the attacker has access to the box as a user? From there it is just a local privilege escalation (which are pretty common) and you have access to everyone else's apps right?