article thumbnail

What The Rails Security Issue Means For Your Startup

www.kalzumeus.com

Rails allows XML documents to include YAML attributes. That decision has caused a bit of head scratching, since it seems like a curious choice for most programmers in the community, but be that as it may this allowed posting XML at Rails apps to be trivially exploited. Rubygems used YAML to hold metadata about each gem submitted to it.

Security 101