You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Jan 9, 2018. It is now read-only.
Either of these vulnerabilities can, depending on the circumstances, lead to full plaintext recovery.
I opened #12 nearly 4 months ago. The extremely severe issue in #4 is approaching 4 years old.
This gem is broken, insecure, and unsuitable for use, and yet it is also the top hit for "ruby aes gem". Please retire it and point people at something safer, like ActiveSupport::MessageEncryptor:
Please retire this gem. It contains multiple, extremely severe security vulnerabilities:
Either of these vulnerabilities can, depending on the circumstances, lead to full plaintext recovery.
I opened #12 nearly 4 months ago. The extremely severe issue in #4 is approaching 4 years old.
This gem is broken, insecure, and unsuitable for use, and yet it is also the top hit for "ruby aes gem". Please retire it and point people at something safer, like
ActiveSupport::MessageEncryptor
:http://api.rubyonrails.org/classes/ActiveSupport/MessageEncryptor.html
The text was updated successfully, but these errors were encountered: