The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default permissions. Users should patch to version 6.3.0. Users unable to patch may correct file permissions after installation.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1031 | The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default permissions. Users should patch to version 6.3.0. Users unable to patch may correct file permissions after installation. |
Github GHSA |
GHSA-x2h8-qmj4-g62f | ROTP 6.2.2 and 6.2.1 has 0666 permissions for the .rb files. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-21T20:41:33.924Z
Reserved: 2024-03-11T22:45:07.686Z
Link: CVE-2024-28862
Updated: 2024-08-02T00:56:58.355Z
Status : Awaiting Analysis
Published: 2024-03-16T00:15:07.570
Modified: 2024-11-21T09:07:03.893
Link: CVE-2024-28862
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA