
Rails 3.2.13, 3.1.12, and 2.3.18 Released: Fix 4 Security Vulnerabilities

So, the next vulnerabilities were found in Rails. This time there are 4 of them:
- CVE-2013-1854 Symbol DoS vulnerability in Active Record
- CVE-2013-1855 XSS vulnerability in sanitize_css in Action Pack
- CVE-2013-1856 XML Parsing Vulnerability affecting JRuby users
- CVE-2013-1857 XSS Vulnerability in the sanitize helper of Ruby on Rails
Vulnerabilities are fixed in versions 3.2.13, 3.1.12, and 2.3.18. It is highly recommended that you upgrade.
More details here .