Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

He tried to warn rails about it, and they closed the issue. Then he reopened it using the bug to show that it was an actual vulnerability, and they closed it again. https://github.com/rails/rails/issues/5228


Agreed. I read this thread, he nicely tries to draw attention to the issue several times, and gets the usual "big corporation pushback": Go away, if it was so important, we'd already know.

Then he proves his point, without hurting anyone. In my book, that deserves an A.


Just to be clear, he did not reopen the issue.


i sent state=open and that worked. technically i opened it without being detected in activity. Typical mass-as-ent bug behavior


You did that with https://github.com/rails/rails/issues/5239 and not https://github.com/rails/rails/issues/5228 as far as I can tell. I was responding to the comment that made it look like the Rails team closed your issue 5228 and you had to re-open it.


Should we consider this a 0-day on Rails?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: