Vulnerabilities (CVE)

Filtered by vendor Ruby-lang Subscribe
Filtered by product Openssl
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-7798 2 Debian, Ruby-lang 2 Debian Linux, Openssl 2020-11-05 5.0 MEDIUM 7.5 HIGH
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.