Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and AESCrypt.decrypt functions, which allows attackers to defeat cryptographic protection mechanisms via a chosen plaintext attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ruby aescrypt gem 安全漏洞
Vulnerability Description
Ruby是日本软件开发者松本行弘所研发的一种跨平台、面向对象的动态类型编程语言。aescrypt gem是用于其中的一个文件加密和解密工具。 Ruby aescrypt gem 1.0.0版本中存在安全漏洞。攻击者可利用该漏洞破坏加密保护机制。
CVSS Information
N/A
Vulnerability Type
N/A