The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default permissions. Users should patch to version 6.3.0. Users unable to patch may correct file permissions after installation.
References
| Link | Resource |
|---|---|
| https://github.com/mdp/rotp/security/advisories/GHSA-x2h8-qmj4-g62f | Vendor Advisory |
| https://github.com/mdp/rotp/security/advisories/GHSA-x2h8-qmj4-g62f | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-03-16 00:15
Updated : 2025-12-05 16:58
NVD link : CVE-2024-28862
Mitre link : CVE-2024-28862
CVE.ORG link : CVE-2024-28862
JSON object : View
Products Affected
rotp_project
- rotp
CWE
CWE-276
Incorrect Default Permissions
