Ruby on Rails(3.2.9, 3.1.8, 3.0.17以å)ã®find_by_*ã¡ã½ããã«SQLã¤ã³ã¸ã§ã¯ã·ã§ã³èå¼±æ§ãè¦ã¤ããã¾ãã(CVE-2012-5664)ããã®ã¨ã³ããªã§ã¯ãã®æ¦è¦ã¨å¯¾çã«ã¤ãã¦èª¬æãã¾ãã æ¦è¦ Ruby on Railsã®find_by_*ã¡ã½ããã®å¼æ°ã¨ãã¦ããã·ã¥ãæå®ãããã¨ã§ãä»»æã®SELECTæãå®è¡ã§ããèå¼±æ§ãããã¾ãã æ¤è¨¼ Ruby on Rails3.2.9ã®ç°å¢ãç¨æãã¦ã以ä¸ã®2ã¤ã®ã¢ãã«ãç¨æãã¾ããã $ rails g scaffold user name:string email:string $ rails g scaffold book author:string title:string ã¢ãã«Userã¯å人æ å ±ãä¿æãã¦ãããèªåèªèº«ã®æ å ±ã®ã¿ãé²è¦§ã§ããã¨ããæ³å®ã§ããã¢ãã«Bookã¯æ¸èªãã¼ã¿ãã¼ã¹ã§ã
{{#tags}}- {{label}}
{{/tags}}