logo

Database

Ruby Short Gcm Auth Tag

Description

Detects usage of short authentication tags in Ruby's OpenSSL GCM (Galois/Counter Mode) encryption which weakens cryptographic security. Short authentication tags (less than 12-16 bytes) make it easier for attackers to forge encrypted messages or perform brute force attacks against the authentication mechanism.

Weakness:

052 - Insecure encryption algorithm

Category: Information Collection

Detection Strategy

    • Scans Ruby source code files that import or use the 'openssl' library

    • Identifies method calls or configurations related to GCM (Galois/Counter Mode) encryption operations

    • Checks if authentication tag length is set to a value shorter than the recommended secure minimum (typically less than 12-16 bytes)

    • Reports vulnerabilities when GCM authentication tags are configured with insufficient length that could compromise message authentication

Vulnerable code example

require 'openssl'

def encrypt_with_weak_auth_tag(key, iv, data)
  cipher = OpenSSL::Cipher.new('aes-256-gcm')
  cipher.encrypt
  cipher.key = key
  cipher.iv = iv
  ...

✅ Secure code example

require 'openssl'

def encrypt_with_weak_auth_tag(key, iv, data)
  cipher = OpenSSL::Cipher.new('aes-256-gcm')
  cipher.encrypt
  cipher.key = key
  cipher.iv = iv
  ...