More information about the security issue is available here: http://www.ruby-lang.org/en/news/2010/08/16/xss-in-webrick-cve-2010-0541/