CVE-2025-0306 DetailsANALYZED This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.
Description A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.
A vulnerability exists in the Ruby interpreter, allowing for the Marvin Attack. This attack enables an attacker to decrypt previously encrypted messages or forge signatures by exchanging a large volume of messages with the affected service. The vulnerability is present in all Ruby versions.
Users can upgrade to Ruby versions that include OpenSSL with the implicit rejection mechanism implemented, such as Ruby 3.2.0 or later. This feature has also been backported to RHEL-8 and RHEL-9.2.
Show AI summary Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 9, 2025 Exploitation: PoCAutomatable: NoTechnical Impact: Total
CISA-ADP
Assessed Jan 9, 2025 Exploitation: NoneAutomatable: NoTechnical Impact: Total
References to Advisories, Solutions, and Tools By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration Affected Products Product Versions Ruby All versions
CPE cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* Remediation Mitigation: low effort Do not use the methods with PKCS#1v1.5 padding in network contexts. Ensure that any calls perform OAEP decryption only and do not support PKCS#1v1.5 encryption padding.
Mitigation: low effort Use Ruby with a version of OpenSSL that has the implicit rejection mechanism implemented. This feature is included in OpenSSL 3.2.0 and has been backported to RHEL-8 and RHEL-9.
NetApp All versions
CPE cpe:2.3:a:netapp:bluexp:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:cloud_backup:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:data_ontap_edge:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:hci:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:max_data:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:netcache:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap_9:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap_tools:*:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:solidfire:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:steelstore:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:storagegrid_webscale:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:system_setup:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:trident:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:500f:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:8300:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:8700:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a220:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a250:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a320:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a400:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a700s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a800:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:aff_500f:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:aff_a300:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:aff_a700:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:aff_a800:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:affa900:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:c190:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:c250:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:c400:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:cn1610:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:ef600a:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas2600:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas26x0:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas2720:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas2750:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas27x0:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas2820:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas_500f:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas500f:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas8200:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas8300:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas_8700:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas8700:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas9000:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h300e:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h300s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410c:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h610c:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h610s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:storagegrid:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:8700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:a220_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:a250_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:a320_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:a400_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:a800_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:aff_a300_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:aff_a700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:aff_a800_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:c190_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:c250_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:c400_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:cluster_data_ontap:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:cn1610_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:data_ontap:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:data_ontap:*:*:*:*:*:7-mode:*:* cpe:2.3:o:netapp:ef600a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas2600_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas26x0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas2720_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas2750_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas27x0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas500f_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas8200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas8300_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas_8700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas8700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas9000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h300e_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h300s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h610c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h610s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:storagegrid_firmware:*:*:*:*:*:*:*:* Remediation No remediation found in references.
Change History 6 change records found show changes