http://www.kalzumeus.com/2013/01/31/what-the-rails-security-...
Regardless, it's an absolute must read for anyone even thinking about using rails.
http://www.kalzumeus.com/2013/01/31/what-the-rails-security-...