Medium severity6.5NVD Advisory· Published Nov 12, 2019· Updated Jun 16, 2026
CVE-2010-3299
CVE-2010-3299
Description
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:rubyonrails:rails:2.3:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rubyonrails:rails:2.3:*:*:*:*:*:*:*
- (no CPE)range: 2.3
- Range: <2.3
Patches
Vulnerability mechanics
References
4- www.usenix.org/legacy/events/woot10/tech/full_papers/Rizzo.pdfnvdExploitThird Party Advisory
- seclists.org/oss-sec/2010/q3/357nvdMailing ListThird Party Advisory
- security-tracker.debian.org/tracker/CVE-2010-3299nvdThird Party Advisory
- access.redhat.com/security/cve/cve-2010-3299nvdBroken Link
News mentions
0No linked articles in our index yet.