Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.

CVSS 1 Total

ScoreSeverityVersionVector String
7.4HIGH3.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Product Status

Learn more

Versions 0 Total

Default Status: All versions are unknown

Versions 0 Total

Default Status: All versions are unknown

Versions 0 Total

Default Status: All versions are unknown

Versions 0 Total

Default Status: All versions are unknown

Versions 0 Total

Default Status: All versions are unaffected

Versions 0 Total

Default Status: All versions are affected

Versions 0 Total

Default Status: All versions are affected

Versions 0 Total

Default Status: All versions are affected

Versions 0 Total

Default Status: All versions are affected

Credits

  • This issue was discovered by Alicja Kario (Red Hat).

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.

Authorized Data Publishers