
SaaS That App - Building Tech-Enabled Businesses · September 1 · 20 min
9.5 CVE, Zero Warning: Inside the Rails Active Storage Bug
0:00-20:54
transcript
show notes
A file-upload vulnerability in Rails Active Storage just scored a 9.5 out of 10 on the severity scale, high enough that, as Justin Edwards puts it: "Everybody stop what you're working on and get this patched." In this episode of SaaS That App, Aaron Marchbanks and Justin break down what made this one so dangerous (anonymous, unprivileged file uploads were enough to compromise a server), why it took two separate patches to actually close the hole, and how they decided which client projects needed a full credential rotation and which didn't.
What You'll Learn:
Got a burning idea for an episode, or a SaaS question you absolutely must know the answer to? Leave us a voice memo: https://www.speakpipe.com/SaasThatApp
Highlights:
Episode Resources:
Saas That App is handcrafted by our friends over at: fame.so
Check out our three most downloaded episodes:
We’d love your feedback. Please take a moment to fill out our audience questionnaire:
https://forms.gle/DN8hWFDcE9jwvNKo6
Your input helps us shape future episodes and continue bringing you practical, real-world insights into building B2B web applications.
What You'll Learn:
- Why this CVE was "as bad as it gets;" vulnerable by default, exploitable by anyone with file upload access, and one step away from full remote code execution
- The real difference between patching a vulnerability and actually remediating it (hint: rolling every API key and secret your app touches)
- How Justin used two real client situations, a three-person beta test vs. a consumer app with thousands of users, to decide when "assume breach" is overkill and when it's non-negotiable
- The concentric circles (and Swiss cheese) framework for layering security so no single failure becomes catastrophic
- Why AI hasn't triggered the predicted vulnerability apocalypse, and might actually be helping more than hurting
- The homeownership metaphor for why "done building" doesn't mean "done maintaining"
Got a burning idea for an episode, or a SaaS question you absolutely must know the answer to? Leave us a voice memo: https://www.speakpipe.com/SaasThatApp
Highlights:
- [01:28] What Is a CVE, Anyway?
- [03:19] The Rails Active Storage Vulnerability Explained
- [06:35] The Race Between Disclosure and Exploitation
- [09:43] When to Roll and When to Accept Risk
- [11:31] Why Environment Isolation Saves You in a Crisis
- [13:52] Is AI Going to Cause a Vulnerability Explosion?
- [14:35] Concentric Circles and Swiss Cheese
- [17:26] Why Every SaaS Founder Needs to Budget as Homeowners
- [19:29] The One Thing Every Team Should Automate
Episode Resources:
- Aaron Marchbanks on LinkedIn
- Justin Edwards on LinkedIn
- CVE Record
- Rails Security Advisory
- Delta Systems Website
Saas That App is handcrafted by our friends over at: fame.so
Check out our three most downloaded episodes:
- AI-Assisted Development: Expectations vs. Reality with Richardson Dackam
- How to Price SaaS for Maximum Growth with Dan Balcauski
- You're Shipping Constantly - So Why Aren't You Growing? With Daniel Layfield
We’d love your feedback. Please take a moment to fill out our audience questionnaire:
https://forms.gle/DN8hWFDcE9jwvNKo6
Your input helps us shape future episodes and continue bringing you practical, real-world insights into building B2B web applications.
links12






