First published: Tue Nov 12 2019(Updated: )
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rubyonrails Rails | =2.3 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
debian/rails | <=2:6.0.3.7+dfsg-2+deb11u2<=2:6.1.7.3+dfsg-2~deb12u1<=2:6.1.7.3+dfsg-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3299 is a vulnerability in Ruby on Rails 2.3 that allows padding oracle attacks.
CVE-2010-3299 has a severity rating of 6.5 (Medium).
Ruby on Rails 2.3, Debian Linux 8.0, Debian Linux 9.0, and Debian Linux 10.0 are affected by CVE-2010-3299.
To fix CVE-2010-3299, update Ruby on Rails to a version that is not vulnerable.
You can find more information about CVE-2010-3299 at the following references: [1] [2] [3].