Rails versions 3.2.10, 3.1.9, and 3.0.18 have been released. These
releases contain an important security fix. It is recommended that all users upgrade immediately.
The security identifier is CVE-2012-5664, and you can read about the
issue [here](add link).
For other change in each particular release, please see the CHANGELOG
corresponding to that version. For all commits in each release, please
follow the links below:
We’re sorry to drop a release like this so close to the holidays but
regrettably the exploit has already been publicly disclosed and we don’t
feel we can delay the release.
To that end, we’ve minimized the number of changes in each release so
that upgrading should be as smooth as possible.
On Wed, Jan 02, 2013 at 01:28:36PM -0800, Aaron P. wrote:
Rails versions 3.2.10, 3.1.9, and 3.0.18 have been released. These releases
contain an important security fix. It is recommended that all users upgrade
immediately.
The security identifier is CVE-2012-5664, and you can read about the issue
[here](add link).