The
POODLE attack (which stands for "
Padding Oracle On Downgraded Legacy Encryption") is a
man-in-the-middle exploit which takes advantage of Internet and security software clients' fallback to
SSL 3.0. If attackers successfully exploit this vulnerability, on average, they only need to make 256 SSL 3.0 requests to reveal one byte of encrypted messages. Bodo Möller, Thai Duong and Krzysztof Kotowicz from the
Google Security Team discovered this vulnerability; they disclosed the vulnerability publicly on October 14, 2014 (despite the paper being dated "September 2014" ). Ivan Ristic does not consider the POODLE attack as serious as the
Heartbleed and
Shellshock attacks. On December 8, 2014 a variation of the POODLE vulnerability that affected
TLS was announced.