3 ms·
This is how I understand the issue as well. Many people in this thread are commenting about massive dangers, but I don't think anyone has bothered to actually r
by jroes 14y ago
This is how I understand the issue as well. Many people in this thread are commenting about massive dangers, but I don't think anyone has bothered to actually read the references in the CVE.
Also, even open source projects typically ensure or recommend that the secret token be regenerated when using in production environments.
- nbpoole 14y agoI think the CVE description is inaccurate in this case. Check out the Rails security email list description, which never mentions sessions. https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/DCNTNp_qjFM https://groups.google.com/forum/?fromgroups=#!topic/rubyonra...