Some Rails users may not be affected (if they only use Rails managed sessions). If users are using the Marshal (default) session cookie encoding, then those users are vulnerable to a Remote Code Execution , after a successful timing attack. While some users may assume that timing atta...