Visit Rails NES Home Page

Rails 2.3.x Release Notes

4 versions

Changelog and Release Notes for the NES version of Rails 2.3

Mar 24, 2026
Latest: 2.3.18.61
117 Patched Vulnerabilities
VEX Statements

March 2026

Bug Fixes

Action View
Active Support

August 2025

Bug Fixes

Active Record
Active Storage

March 2025

2.3.18.59

Released Mar 17, 2025

Notes

  • Removed the railslts-version gem.

February 2025

Notes

  • This is the initial release of Never-Ending Support (NES) for Rails v2.3.x.

Bug Fixes

Action Mailer
Action Pack
  • CVE-2023-28362 – Raise an exception if illegal characters are provide to redirect_to.
  • CVE-2021-22885 – Fixed an information disclosure and unintended method execution vulnerability in Action Pack.
  • CVE-2020-8159 - Arbitrary file write/potential remote code execution attack.
  • CVE-2016-0751 – Fixed a denial-of-service (DoS) vulnerability caused by a crafted HTTP Accept header.
Active Record
  • CVE-2022-44566– Fixed a denial-of-service (DoS) vulnerability in Active Record's PostgreSQL adapter.
  • CVE-2022-32224 – Fixed a remote code execution (RCE) vulnerability with serialized columns in Active Record.
  • CVE-2014-3482 – Fixed a SQL injection vulnerability in Active Record.
Active Resource
  • CVE-2020-8151 – Fixed an information disclosure issue in Active Resource.
Active Support
  • CVE-2015-3227 - Fixed Active Support vulnerable to Denial of Service via large XML document depth

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.