Loading…

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]
To respect copyright, we link to the source rather than republishing the full text. Read the complete article on BleepingComputer.