CVE detail
CVE-2011-2705 — CVE-2011-2705
Published 2011-08-05 · Modified 2026-06-16 · Vendor ruby-lang · Product ruby · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0195
EPSS probability
exploitation probability, 30d
78.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References