Rails has released security patches for versions 7.1.5.2, 7.2.2.2, and 8.0.2.1 addressing two security issues including an Active Storage vulnerability and ANSI escape injection. The Active Storage vulnerability is not exploitable under default configuration, and the ANSI escape injection has minimal impact under most terminals. Users are recommended to upgrade as soon as possible, especially those on older unsupported versions who should move to at least the 7.1 series.
Sort: