CVE-2025-0306

CVSS 3.1 Score 7.4 of 10 (high)

Details

Published Jan 9, 2025
Updated: Feb 21, 2025
CWE ID 385

Summary

CVE-2025-0306 is a newly disclosed vulnerability affecting the Ruby interpreter. This issue, known as the Marvin Attack, enables an attacker to decrypt previously encrypted messages or forge signatures by engaging in extensive message exchanges with the vulnerable service. The Ruby interpreter's weakness lies in its inability to handle large numbers of messages effectively, making it susceptible to this type of attack. This vulnerability poses a significant risk to applications and services that rely on the Ruby interpreter for encryption and signature verification. Users are advised to apply the available patch or upgrade to a patched version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share