DEV Community

Cover image for Today’s rails security update in plain english

Today’s rails security update in plain english

Alex Sharp 🛠sharesecret.co on March 14, 2019

Cross-posted from the ShareSecret blog. Earlier today the Rails team pushed new versions to patch three security vulnerabilities: CVE-2019-5...
Collapse
 
terabytetiger profile image
Tyler V. (he/him)

Alarm level: Five alarm fire. Patch immediately.

Alarm level: Not good, but go back to sleep. Fix it in the morning.

I think we need more breakdowns that use this type of "in your face. Here's how urgent this is" language for security patches. Not in place of the technical details, but preferably in addition to.

As someone that's involved with Rails to the extent of 'maybe I installed it at some point', this article was easy to follow. Great write-up!

Collapse
 
ajsharp profile image
Alex Sharp 🛠sharesecret.co

Hey thanks, I appreciate it, and I agree! There are so many security updates, and it's easy to pass over them when you read the headline.

Collapse
 
cyc115 profile image
Mike Chen

Rails development mode RCE is a bad one depending on your network layout. A development server can quickly become a pivot point to internal networks if the network is not well segmented.

Collapse
 
ajsharp profile image
Alex Sharp 🛠sharesecret.co

Yea, that's a great point. I'll update the post with a blurb about that.

Collapse
 
bobwalsh profile image
Bob Walsh

Hey Thanks Alex for sorting out security issues that matter from the noise - will start following your posts!