VDB
Sign up
HIGH7.5

GHSA-6h88-qjpv-p32m

OpenSSL gem for Ruby using inadequate encryption strength

Quick fix

GHSA-6h88-qjpv-p32m — openssl: upgrade to the fixed version with the command below.

bundle update openssl

Details

The OpenSSL gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/openssl
Introduced in: 0Fixed in: 2.0.0
Fixbundle update openssl

References