Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ruby openssl gem 加密问题漏洞
Vulnerability Description
Ruby是日本软件开发者松本行弘所研发的一种跨平台、面向对象的动态类型编程语言。Ruby openssl gem是其中的一个开源的能够实现安全套接层(SSL v2/v3)和安全传输层(TLS v1)协议的通用加密库。 Ruby openssl gem中存在安全漏洞。攻击者可利用该漏洞绕过加密保护机制。
CVSS Information
N/A
Vulnerability Type
N/A