Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6h88-qjpv-p32m

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

OpenSSL gem for Ruby using inadequate encryption strength

The OpenSSL gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

Пакеты

Наименование

openssl

rubygems
Затронутые версииВерсия исправления

< 2.0.0

2.0.0

EPSS

Процентиль: 68%
0.00597
Низкий

7.5 High

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

CVSS3: 3.7
redhat
около 9 лет назад

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

CVSS3: 7.5
nvd
почти 9 лет назад

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

CVSS3: 7.5
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 7.5
debian
почти 9 лет назад

The openssl gem for Ruby uses the same initialization vector (IV) in G ...

EPSS

Процентиль: 68%
0.00597
Низкий

7.5 High

CVSS3

Дефекты

CWE-326