aboutsummaryrefslogtreecommitdiffstats
path: root/railties
diff options
context:
space:
mode:
authorMichael Koziarski <michael@koziarski.com>2013-11-30 16:45:23 +1300
committerAaron Patterson <aaron.patterson@gmail.com>2013-12-02 14:14:35 -0800
commitd5a4095ca5725d5eebcce153d7d0738375146cef (patch)
tree328632b6185b19991f7d86f67889fa42977197e0 /railties
parent78790e4bceedc632cb40f9597792d7e27234138a (diff)
downloadrails-d5a4095ca5725d5eebcce153d7d0738375146cef.tar.gz
rails-d5a4095ca5725d5eebcce153d7d0738375146cef.tar.bz2
rails-d5a4095ca5725d5eebcce153d7d0738375146cef.zip
Deep Munge the parameters for GET and POST
The previous implementation of this functionality could be accidentally subverted by instantiating a raw Rack::Request before the first Rails::Request was constructed. Fixes CVE-2013-6417 Conflicts: actionpack/lib/action_dispatch/http/request.rb
Diffstat (limited to 'railties')
0 files changed, 0 insertions, 0 deletions