Hacker News new | ask | show | jobs
by nbpoole 4919 days ago
I think the CVE description is inaccurate in this case. Check out the Rails security email list description, which never mentions sessions.

https://groups.google.com/forum/?fromgroups=#!topic/rubyonra...