Ruby on Rails Missing Encryption of Sensitive Data Vulnerability (CVE-2010-3299)
Description
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.