Our takeCanadian Cyber Centre issued a Rails security advisory covering three branches. Update to 8.0.5.1, 8.1.3.1 or 7.2.3.2.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Update Rails to 8.0.5.1, 8.1.3.1 or 7.2.3.2 (or later) immediately. The CCCS advisory confirms active risk in all prior versions of the three supported branches.
What this means for you — Lean IT orgs:If your website or internal tools run on Ruby on Rails, update to version 8.0.5.1, 8.1.3.1 or 7.2.3.2 right away. Most lean-IT teams can do this with a single command from your hosting provider.
What this means for you — MSP:Audit every client Rails app for versions prior to 8.0.5.1, 8.1.3.1 or 7.2.3.2 and push the updates. This advisory covers all three currently supported branches.
What this means for you — Researcher:Review the upstream GitHub releases (7.2.3.2, 8.0.5.1, 8.1.3.1) and any associated CVEs once they are published.