Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As far as I understand, Rack is not vulnerable unless the underlaying Ruby interpreter is vulnerable, like old 1.8, Rubinius, older JRuby.

Rack introduced a workaround in https://github.com/rack/rack/commit/5b9d09a81a9fdc9475f0ab00...

this may help in some cases when an interpreter fix is not available/installable but not fix the hashing problem in general, especially outside of POST params.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: