security.nuyts.tech
CVE-2011-3187 – NuytsTech Security
The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from I