Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Untriaged
created 1 month, 3 weeks ago
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable …

The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.

References

Affected products

rails
  • ==2.3

Matching in nixpkgs

pkgs.rails-new

Generate new Rails applications without having to install Ruby

Package maintainers