Description
The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default permissions. Users should patch to version 6.3.0. Users unable to patch may correct file permissions after installation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1031 | The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default permissions. Users should patch to version 6.3.0. Users unable to patch may correct file permissions after installation. |
Github GHSA |
GHSA-x2h8-qmj4-g62f | ROTP 6.2.2 and 6.2.1 has 0666 permissions for the .rb files. |
References
History
Fri, 03 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:rotp_project:rotp:6.2.2:*:*:*:*:ruby:*:* |
cpe:2.3:a:rotp_project:rotp:*:*:*:*:*:ruby:*:* |
Fri, 05 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rotp Project
Rotp Project rotp |
|
| CPEs | cpe:2.3:a:rotp_project:rotp:6.2.1:*:*:*:*:ruby:*:* cpe:2.3:a:rotp_project:rotp:6.2.2:*:*:*:*:ruby:*:* |
|
| Vendors & Products |
Rotp Project
Rotp Project rotp |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-21T20:41:33.924Z
Reserved: 2024-03-11T22:45:07.686Z
Link: CVE-2024-28862
Updated: 2024-08-02T00:56:58.355Z
Status : Analyzed
Published: 2024-03-16T00:15:07.570
Modified: 2026-04-03T13:57:33.140
Link: CVE-2024-28862
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA