Rails Directory Traversal Vulnerability (CVE-2014-0130)
groups.google.com
groups.google.com
17 results https://github.com/search?l=Ruby&q=routes+%2Aaction&ref=sear...
Obviously there are some apps that will be vulnerable, but they will likely be very rare.
That should be something like /\A(http(s?):\/\/#{request.host_with_port}|\/\Z|\/[^\/])/
Now it will hit the front page and everyone will rant how vulnerable rails is not reading the details. Same happened with "oauth covert redirect" (which is nothing interesting) few days ago.
https://groups.google.com/forum/#!topic/rubyonrails-security...