Rails 3.2.18, 4.0.5 and 4.1.1 have been released
weblog.rubyonrails.org
weblog.rubyonrails.org
A bad actor could easily modify these in a proxy etc when serving the page.
Edit: Unless the purpose isn't to prevent tampering, but for error-correction.
I believe this script[1] should expose some of those dangerous columns. There's still the join alias risk, but I'm not sure, other than parsing a schema.rb, how to get at those effectively.
[0] https://groups.google.com/forum/#!topic/rubyonrails-security...
[1] https://gist.github.com/KevinMcHugh/fab941ec3677f9a19ee0
[1]https://groups.google.com/forum/#!topic/rubyonrails-security...