Merged upstream bug fix for [CVE-2022-32224] Possible RCE escalation bug with Serialized Columns in Active Record. We tried to make it less of a breaking change than the official patch by adding a default set of permitted serializable classes. see details
May 18th, 2022: Version 126.96.36.199
Merged upstream bug fix for recent security fix for CVE-2022-27777 and improved it; see detailsArchive
Apr 27th, 2022: Version 188.8.131.52
Merged upstream fixes for CVE-2022-22577 and CVE-2022-27777, to include CSP headers on all all responses, and fixing possible XSS vulnerabilities via content_tag or tag helpers; see detailsArchive
Mar 12th, 2022: Version 184.108.40.206
Merged upstream fix for loading image processing arguments with incorrect order. see hereArchive
Mar 09th, 2022: Version 220.127.116.11
Merged upstream fix for CVE-2022-21831, which fixes a potential code injection vulnerability in ActiveStorage by adding an allowlist to image processing methods, in case user input is passed to the #variant method. see hereArchive
Feb 12th, 2022: Version 18.104.22.168
Merged upstream fix for CVE-2022-23633, addressing potential cross-request information leakage in Action Pack. see hereArchive
Dec 09th, 2021: Version 22.214.171.124
Initial release of the LTS version of Rails 5.2.
This is identical to the official 5.2.6 release, except for the additional Rails LTS hardening config. This config currently has no effect but might be used for future fixes (in which case the advisory will point that out).
Supports Ruby 2.2, 2.5, and 2.7.
(Skipped to version .10 to avoid collision with a potential future 126.96.36.199 community release.)