CVE-2010-3299: Medium severity rubyonrails Rails vulnerability
Published Nov 12, 2019
·Updated
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
Affected Software
5 affected components
rubyonrails Rails=2.3
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/rails<=2:6.0.3.7+dfsg-2+deb11u2, <=2:6.0.3.7+dfsg-2+deb11u4, <=2:6.1.7.10+dfsg-1~deb12u2, <=2:7.2.2.2+dfsg-2~deb13u1, <=2:7.2.2.2+dfsg-2
Event History
Nov 12, 2019
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
DescriptionWeakness
Feb 17, 2026
Data Sourced
via Debian·10:09 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2010-3299?
CVE-2010-3299 is a vulnerability in Ruby on Rails 2.3 that allows padding oracle attacks.
2
How severe is CVE-2010-3299?
CVE-2010-3299 has a severity rating of 6.5 (Medium).
3
Which software is affected by CVE-2010-3299?
Ruby on Rails 2.3, Debian Linux 8.0, Debian Linux 9.0, and Debian Linux 10.0 are affected by CVE-2010-3299.
4
How do I fix CVE-2010-3299?
To fix CVE-2010-3299, update Ruby on Rails to a version that is not vulnerable.
5
Where can I find more information about CVE-2010-3299?
You can find more information about CVE-2010-3299 at the following references: [1] [2] [3].