Government Rails Site Hit Hours After CVE Patch

78 points - yesterday at 7:06 PM

Source

Comments

throwatdem12311 today at 12:41 AM
Just sent this to my boss. Felt like tossing a grenade over a fence into a party of unsuspecting people.

We donโ€™t use ActiveStorage but Claude was able create a similar exploit in own our app in the exact same way via our own file upload library in 3 minutes simply by point Opus 5 at our site and asking it if we were vulnerable to an attack similar to KindaRails2Shell.

What a time to be alive.

deleted today at 12:16 AM
jeremyjh today at 12:05 AM
Nice write up, Claude.
onemoresoop today at 2:13 AM
This website is format is really weird for mobile, I can only read two lines of text. The rest is covered by a big banner. Im on IOS. Anybody else having this issue or is it just me?
tyre yesterday at 9:18 PM
This post could be 10% as long:

- There was a bug with a patch

- We applied it to our clients

- There were live exploits within eight hours of the patch being released

- The Rails team had to expedite release of the technical details because POCs obviated the need to embargo

comrade1234 yesterday at 7:41 PM
Do you have to have matlab running on your rails server for this to happen?
dorianmariecom yesterday at 7:38 PM
i thought cloudflare would protect against those no?
hobonation yesterday at 9:12 PM
[dead]
shevy-java yesterday at 9:08 PM
DHH needs to focus on Rails again rather than Omarchy.
kazinator today at 12:52 AM
> That is about as bad as it gets and meant that any delay in patching was an existential risk of imminent compromise.

Overdramatized.

It means compromise if you delay patching and don't take the unpatched deployment offline.

Oh right, this is government sites; every second of down time is lost revenue.