5 ms·
Rails 4.0.9 and 4.1.5 have been released
- dmix 12y agoBriefly searching Github for create_with it seems to be mostly used with seed data and or test factory models. https://github.com/search?l=Ruby&q=create_with&ref=cmdform&type=Code&utf8=%E2%9C%93 https://github.com/search?l=Ruby&q=create_with&ref=cmdform&t... Although quite a few taking raw user input. I'd imagine not all of them are Rails 4+ though.
- Siecje 12y agoI'm impressed with how few issues Rails has right now.
- scott_karana 12y agoI agree! I last updated to 4.1.1, and none of the security patches since then have been relevant to my codebase or included gems, so far.
- stouset 12y agoDon't be so sure with this one. They only disclosed the `create_with` issue, but `where(params).create` was also vulnerable. Unfortunately, the latter is much harder to search for and more likely to be used since `where` is seemingly safe.
- scott_karana 12y agoI have a very, very small codebase for my single application, so I'm sure: RoR beginner here, it's my first project. ;) But that's a pretty thoughtful warning for others, upvoted!
- lectrick 12y agoProbably because it's not experiencing a ton of new features right now.
- stouset 12y agoI reported this. Curiously, they patched (but didn't disclose) the more severe half of this bug. Calls to `Model.where(params).create` also don't protect against mass-assignment. I believe this pattern is both much more prevalent and hard to detect.
- lectrick 12y agoNow with less TDD!