Ruby on Rails versions 3.2.18, 4.0.5 and 4.1.1 are available for download. The updates address a serious vulnerability so users are advised to update their installations as soon as possible.
The vulnerability has been assigned the CVE identifier CVE-2014-0130 and it affects all supported versions of Ruby on Rails. It impacts the implicit render functionality which allows controllers to render a template even if theres no explicit action with the correspondent name.
…