TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Unsafe Query Generation Risk in Ruby on Rails (CVE-2013-0155)

47 点作者 Pr0超过 12 年前

4 条评论

Pr0超过 12 年前
Not as serious as <a href="http://news.ycombinator.com/item?id=5028218" rel="nofollow">http://news.ycombinator.com/item?id=5028218</a> but still important to note.
alexkus超过 12 年前
Thanks<p>Is there a site I can sign up for package update notifications for a bunch of projects?<p>I don't want info on all CVEs or all system packages but just a list of packages I'm interested in (and more than just ubuntu/Debian packages).<p>I seem to remember one site on HN but my google-fu is weak tonight...
评论 #5028982 未加载
teyc超过 12 年前
Please, if anyone's reading this, do not release a proof-of-concept until everyone has a chance to patch. (I sense there are a lot of already busy Rails developers today).<p>By the way, what do freelancers on HN feel about general responsibility for security maintenance after the work has been done?
评论 #5030245 未加载
TallboyOne超过 12 年前
What an interesting day