KindaRails2Shell abuses a file that tells two different libraries two different lies to read anything your Rails app can read — including the keys…
The short version
The short version
The short version
The short version
The short version
The part that should worry you more than the CVE score
Aliteq
a Rails image upload bug lets a file lie about what it is — and steal your app's secret keys