The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly permissive default permissions. Users should patch to version 6.3.0. Users unable to patch may correct file permissions after installation.
References
| Link | Resource |
|---|---|
| https://github.com/mdp/rotp/security/advisories/GHSA-x2h8-qmj4-g62f | Vendor Advisory |
| https://github.com/mdp/rotp/security/advisories/GHSA-x2h8-qmj4-g62f | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
05 Dec 2025, 16:58
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/mdp/rotp/security/advisories/GHSA-x2h8-qmj4-g62f - Vendor Advisory | |
| CPE | cpe:2.3:a:rotp_project:rotp:6.2.2:*:*:*:*:ruby:*:* cpe:2.3:a:rotp_project:rotp:6.2.1:*:*:*:*:ruby:*:* |
|
| First Time |
Rotp Project
Rotp Project rotp |
21 Nov 2024, 09:07
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/mdp/rotp/security/advisories/GHSA-x2h8-qmj4-g62f - |
16 Mar 2024, 00:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-03-16 00:15
Updated : 2025-12-05 16:58
NVD link : CVE-2024-28862
Mitre link : CVE-2024-28862
CVE.ORG link : CVE-2024-28862
JSON object : View
Products Affected
rotp_project
- rotp
CWE
CWE-276
Incorrect Default Permissions
