Lucene search

K
osvGoogleOSV:GHSA-6H88-QJPV-P32M
HistoryOct 24, 2017 - 6:33 p.m.

OpenSSL gem for Ruby using inadequate encryption strength

2017-10-2418:33:35
Google
osv.dev
16

EPSS

0.004

Percentile

73.1%

The OpenSSL gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.