Hacker News new | past | comments | ask | show | jobs | submit login

Um... have you read the linked posting?

>Carefully crafted requests can use the scope to inject >arbitrary SQL.

It's also titled "SQL Injection Vulnerability". Are we all missing something?




um um um you sound like an idiot. shut up already you've failed to redeem and save face.


You're the one calling people names. The guy who wrote the fix that was actually accepted by the Rails core team called this a "SQL Injection" and it has been filed in that category by numerous independent bug trackers.

I don't quite understand the angst about this defect being called a SQL injection vulnerability. The vector for the attack doesn't change the end result.

The cause might be that the API was broken, but it doesn't change the fact that a guy wrote SQL code that was injected into the middle of the rest of the SQL generated by the ORM.




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: