The Ruby on Rails open source web framework has been updated to close a security hole in the translate helper method. According to the developers, a cross-site scripting (XSS) vulnerability in the helper method for i18n translations could be exploited by an attacker to insert arbitrary code into a page. . Rails 3.0.0 and later, as well as 2.3.x in combination with the rails_xss plug-in, are affected. Upgrading to 3.0.11 or 3.1.2 corrects the issue; the updates also address several non-security-related bugs. The link for this article located at H Security is no longer available. . Rails has patched a critical XSS flaw impacting all versions starting from 3.0.0, enhancing defenses against potential code injection threats.. Ruby on Rails Security, XSS Exploit Fix, Web Framework Update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.