I.e., they have been grossly negligient in their server maintenance for most of this year. http://www.kalzumeus.com/2013/01/31/what-the-rails-security-...
[Edit: although at least one mentions 3.2.11, which should have that particular vulnerability fixed, so it will probably at least sometimes be someting else.]