ActiveRecord :limit & :offset hole

  • Check your apps for this security hole:

        cd /my/rails/app.git
        grep -rnP :limit\.+:offset ./app/