colah / implicitcad.org

Website for ImplicitCAD
www.implicitcad.org
GNU Affero General Public License v3.0
10 stars 5 forks source link

Updates rack to prevent security vuln #7

Closed f3ndot closed 7 years ago

f3ndot commented 11 years ago

Updates rack and a few other Rails dependencies to patch against:

CVE-2013-0263: timing attack against Rack::Session::Cookie CVE-2013-0262: symlink path traversal in Rack::File

Source: https://groups.google.com/forum/#!msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ