Please Install the Updated Packages.
This update updates the RubyOnRails 2.3 stack to 2.3.16, also this update updates the RubyOnRails 3.2 stack to 3.2.11. Security and bugfixes were done, foremost: CVE-2013-0333: A JSON sql/code injection problem was fixed. CVE-2012-5664: A SQL Injection Vulnerability in Active Record was fixed. CVE-2012-2695: A SQL injection via nested hashes in conditions was fixed. CVE-2013-0155: Unsafe Query Generation Risk in Ruby on Rails was fixed. CVE-2013-0156: Multiple vulnerabilities in parameter parsing in Action Pack were fixed.
ruby on openSUSE 12.1
Updated on 2015-03-25
CVE CVE-2012-2695, CVE-2012-5664, CVE-2013-0155, CVE-2013-0156, CVE-2013-0333
CVSS Base Score: 7.5