GHSA-x2h8-qmj4-g62f

Source
https://github.com/advisories/GHSA-x2h8-qmj4-g62f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-x2h8-qmj4-g62f/GHSA-x2h8-qmj4-g62f.json
Aliases
  • CVE-2024-28862
Published
2024-03-18T17:21:46Z
Modified
2024-03-19T18:46:07.051349Z
Details

The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default permissions. Users should patch to version 6.3.0. Users unable to patch may correct file permissions after installation.

References

Affected packages

RubyGems / rotp

Package

Name
rotp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.1
Fixed
6.3.0

Affected versions

6.*

6.2.1
6.2.2