Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-0306

Опубликовано: 24 июн. 2024
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

Отчет

More information about the Marvin Attack may be found at https://www.redhat.com/en/blog/marvin-attack.

Меры по смягчению последствий

See the following possible mitigations for this flaw:

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rubyOut of support scope
Red Hat Enterprise Linux 7rubyOut of support scope
Red Hat Enterprise Linux 8ruby:2.5/rubyOut of support scope
Red Hat Enterprise Linux 8ruby:3.1/rubyOut of support scope
Red Hat Enterprise Linux 8ruby:3.3/rubyNot affected
Red Hat Enterprise Linux 9rubyWill not fix
Red Hat Enterprise Linux 9ruby:3.1/rubyWill not fix
Red Hat Enterprise Linux 9ruby:3.3/rubyWill not fix
Red Hat Storage 3rubyAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-385

EPSS

Процентиль: 50%
0.0027
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
11 месяцев назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

CVSS3: 7.4
nvd
11 месяцев назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

CVSS3: 7.4
debian
11 месяцев назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable ...

CVSS3: 7.4
redos
9 месяцев назад

Уязвимость ruby

CVSS3: 7.4
github
11 месяцев назад

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

EPSS

Процентиль: 50%
0.0027
Низкий

7.4 High

CVSS3