Versions 3.2.16 and 4.0.2 of Ruby on Rails have been released to address a number of important security issues. Users are advised to update their installations as soon as possible. There are four vulnerability fixes in both variants. The list includes an unsafe query generation risk caused by an incomplete fix to an older bug, reflected cross-site scripting (XSS) in the internationalization component of Ruby on Rails, XSS in the number_to_currency helper, and a denial-of-service (…