He tried to warn rails about it, and they closed the issue. Then he reopened it using the bug to show that it was an actual vulnerability, and they closed it again. https://github.com/rails/rails/issues/5228
Agreed. I read this thread, he nicely tries to draw attention to the issue several times, and gets the usual "big corporation pushback": Go away, if it was so important, we'd already know.
Then he proves his point, without hurting anyone. In my book, that deserves an A.