So I'm digging around in the Rack source right now trying to see what's up, I haven't seen anywhere that it doesn't just rely on the native Ruby Hash class.
Does anybody closer to the matter know if Rack's actually vulnerable in 1.9?
this may help in some cases when an interpreter fix is not available/installable but not fix the hashing problem in general, especially outside of POST params.
Does anybody closer to the matter know if Rack's actually vulnerable in 1.9?