I gave this presentation at an internal Oracle tech talk to serve as a primer on a few common security vulnerabilities in Rails applications. The mentioned bug was in a new feature buried behind a beta flag and didn't actually affect any customers, but it's always good to refresh everyone on things like this that can easily slip into large projects unnoticed.