CVE-2025-0306

Public on 2025-01-09
Modified on 2025-01-10
Description
A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.
Severity
Medium severity
Medium
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 1 ruby No Fix Planned
HAQM Linux 2 - Core ruby Pending Fix
HAQM Linux 1 ruby18 No Fix Planned
HAQM Linux 1 ruby19 No Fix Planned
HAQM Linux 1 ruby20 No Fix Planned
HAQM Linux 1 ruby21 No Fix Planned
HAQM Linux 1 ruby22 No Fix Planned
HAQM Linux 1 ruby23 No Fix Planned
HAQM Linux 1 ruby24 No Fix Planned
HAQM Linux 2023 ruby3.2 Pending Fix

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
NVD CVSSv3 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N