Ruby Short Gcm Auth Tag
Description
Detects usage of short authentication tags in Ruby's OpenSSL GCM (Galois/Counter Mode) encryption which weakens cryptographic security. Short authentication tags (less than 12-16 bytes) make it easier for attackers to forge encrypted messages or perform brute force attacks against the authentication mechanism.
Detection Strategy
• Scans Ruby source code files that import or use the 'openssl' library
• Identifies method calls or configurations related to GCM (Galois/Counter Mode) encryption operations
• Checks if authentication tag length is set to a value shorter than the recommended secure minimum (typically less than 12-16 bytes)
• Reports vulnerabilities when GCM authentication tags are configured with insufficient length that could compromise message authentication
Vulnerable code example
require 'openssl'
def encrypt_with_weak_auth_tag(key, iv, data)
cipher = OpenSSL::Cipher.new('aes-256-gcm')
cipher.encrypt
cipher.key = key
cipher.iv = iv
...✅ Secure code example
require 'openssl'
def encrypt_with_weak_auth_tag(key, iv, data)
cipher = OpenSSL::Cipher.new('aes-256-gcm')
cipher.encrypt
cipher.key = key
cipher.iv = iv
...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.