The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
References
Configurations
History
No history.
Information
Published : 2017-01-30 22:59
Updated : 2025-04-20 01:37
NVD link : CVE-2016-7798
Mitre link : CVE-2016-7798
CVE.ORG link : CVE-2016-7798
JSON object : View
Products Affected
ruby-lang
- openssl
debian
- debian_linux
CWE
CWE-326
Inadequate Encryption Strength