So what is the exploit, and how do we fix it?
Rails has been updated to close these particular vulnerabilities. The proper versions are listed in these two advisories. There are also work-arounds if your app is not in a state to just upgrade Rails. If your app is in that state, I strongly advise you that your only priority for the next several days is fixing that, because one should have high confidence that there will be more vulnerabilities announced soonish.
https://groups.google.com/forum/?fromgroups=#!topic/rubyonra...
https://groups.google.com/forum/?fromgroups=#!topic/rubyonra...