Rails团队声称,此次更新包含了大量的安全修复,因此请尽快升级。
4.1.11和4.2.2的安全修复:
CVE-2015-3226
CVE-2015-3227
为了用户尽可能流畅升级,Rails针对每一个安全问题直接提供了相关的更新。
3.2.22的安全修复:
CVE-2015-3227
与Rails 4发布不同,Rails 3.2.22包含了所有来自3-2-stable分支的commits,这意味着现在的Rails 3.2支持Ruby 2.2。
3.2.22的commits可以点击这里获取;4.1.11的commits可以点击这里获取;4.2.2可点击这里获取。
Web Console
Rails还发布了Web Console 2.1.3,包含了以下问题的修复:
CVE-2015-3224
Web Console 2.1.3的commits可点击这里获取。
jQuery-UJS和jQuery-Rails
Rails还发布了jQuery-UJS 1.0.4、jQuery-Rails 3.1.3和4.0.4,包含了以下问题的修复:
CVE-2015-1840
jQuery-Rails 3.1.3的commits可点击这里获取;jQuery-Rails 4.0.4的commits可点击这里获取;jQuery-UJS 1.0.4的commits可点击这里获取。
Rack
Rack 1.5.4和Rack 1.6.2也已发布,包含了以下问题的修复:
CVE-2015-3225
Rack 1.5.4的commits可点击这里获取;Rack 1.6.2的commits可点击这里获取。
SHA-1
Rails 3.2.22的checksums:
$ shasum *3.2.22*
cc56be2f49baeeccc0da87b740f23d0ac7bd2d24 actionmailer-3.2.22.gem
d20fd24d9049fad99ea5405a265ca7c9690af378 actionpack-3.2.22.gem
0454b4bd49a1a423e1ef6231a5cb510ca48e0cb8 activemodel-3.2.22.gem
d9e51980eb4892089a29531c1fea69cabe9511e4 activerecord-3.2.22.gem
3754c63826f09b6b10bd0ca749646f76fbe195c6 activeresource-3.2.22.gem
4da01bbf6e03326c24c261c3d65a8c0b563f8663 activesupport-3.2.22.gem
0386d4d55b52d1348e024cb237e3b81126ce6c46 rails-3.2.22.gem
56575ff805b432be10fa79080c25c790947999f2 railties-3.2.22.gem
Rails 4.1.11的checksums:
$ shasum *4.1.11*
154856eb9c940e8fb5c999b08c748ce82e8a1197 actionmailer-4.1.11.gem
fa9a8271d8c19af89f8cf46c9a5bfd0b3ece1226 actionpack-4.1.11.gem
340678573b91ad305b9c2b07844d0628dbcf6a8d actionview-4.1.11.gem
c56dc176a7ac0690d4f59472f28b36a664221d5c activemodel-4.1.11.gem
711334da9e88d8d2606b4e12df115b093fb3a1b1 activerecord-4.1.11.gem
b714633af191481332797ed09f62fdd784363fb1 activesupport-4.1.11.gem
9fc1c823457ffe51cc6f52de2960035149621e15 rails-4.1.11.gem
1640674035171d0eb36ff91da9ea8d86f2137261 railties-4.1.11.gem
Rails 4.2.2的checksums:
$ shasum *4.2.2*
a093bdd43d732416f02b1cc39edc4f839b27cc69 actionmailer-4.2.2.gem
51dc701f026f3a84a779287459996f36023877f9 actionpack-4.2.2.gem
6ae3231fa1e6bbd07b4d1bf7b124654b39f3e048 actionview-4.2.2.gem
16e607a30b41d000bae2e848c11ef472264a5d94 activejob-4.2.2.gem
e667fb6dee998be2d1d01086467fa3fe2ca58dff activemodel-4.2.2.gem
394cc4d39e8c84c2aed5b25c352cd6b2903ab686 activerecord-4.2.2.gem
b4b91de89a8c6f223bed5c01a7e578956d4a2bf7 activesupport-4.2.2.gem
a9e286e6799bde99e1449706854b910b5c466302 rails-4.2.2.gem
dd46d7f599fb883c1d3fd6b5ec8fcfd61628b869 railties-4.2.2.gem
Web Console 2.1.3的checksum:
$ shasum web-console-2.1.3*
60aed82466891904d7348583d67ec7dabce3a176 web-console-2.1.3.gem
jQuery-Rails 3.1.3和4.0.4的checksums:
$ shasum jquery-rails*.gem
691b6ec57ee08f8ef80bae3e8c09a4442d2f7d5c jquery-rails-3.1.3.gem
159b4127ebbaba708cbed2921d1d1b00134ee834 jquery-rails-4.0.4.gem
Rack 1.5.4和1.6.2的checksums:
$ shasum rack-*.gem
d71ea9c90d7ef2a0787722f233da8fcbfb5e55d5 rack-1.5.4.gem
85d34dbf068cda5cf36432984da8ccf81c3d1be5 rack-1.6.2.gem