CVE-2024-28862

MEDIUM

rotp 6.2.1-6.2.9 - Incorrect Default Permissions

Title source: llm
STIX 2.1

Description

The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default permissions. Users should patch to version 6.3.0. Users unable to patch may correct file permissions after installation.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 14.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (4)
rotp_project/rotp 6.2.1
rotp_project/rotp 6.2.2
rotp_project/rotp 6.2.1 - 6.3.0
rubygems/rotp 6.2.1 - 6.3.0RubyGems
Published Mar 16, 2024
Tracked Since Feb 18, 2026