Ruby on Rails Missing Encryption of Sensitive Data Vulnerability - CVE-2010-3299
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.