Логотип exploitDog
bind:"GHSA-j4pr-3wm6-xx2r" OR bind:"CVE-2025-61594"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-j4pr-3wm6-xx2r" OR bind:"CVE-2025-61594"

Количество 12

Количество 12

github логотип

GHSA-j4pr-3wm6-xx2r

3 месяца назад

URI Credential Leakage Bypass over CVE-2025-27221

EPSS: Низкий
ubuntu логотип

CVE-2025-61594

3 месяца назад

URI is a module providing classes to handle Uniform Resource Identifiers. In versions prior to 0.12.5, 0.13.3, and 1.0.4, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the `+` operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. Versions 0.12.5, 0.13.3, and 1.0.4 fix the issue.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-61594

3 месяца назад

URI is a module providing classes to handle Uniform Resource Identifiers. In versions prior to 0.12.5, 0.13.3, and 1.0.4, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the `+` operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. Versions 0.12.5, 0.13.3, and 1.0.4 fix the issue.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-61594

3 месяца назад

URI is a module providing classes to handle Uniform Resource Identifiers. In versions prior to 0.12.5, 0.13.3, and 1.0.4, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the `+` operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. Versions 0.12.5, 0.13.3, and 1.0.4 fix the issue.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-61594

3 месяца назад

URI Credential Leakage Bypass over CVE-2025-27221

EPSS: Низкий
debian логотип

CVE-2025-61594

3 месяца назад

URI is a module providing classes to handle Uniform Resource Identifie ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2025:23141

3 месяца назад

Moderate: ruby security update

EPSS: Низкий
rocky логотип

RLSA-2025:23063

3 месяца назад

Moderate: ruby:3.3 security update

EPSS: Низкий
rocky логотип

RLSA-2025:23062

3 месяца назад

Moderate: ruby:3.3 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23141

4 месяца назад

ELSA-2025-23141: ruby security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23063

4 месяца назад

ELSA-2025-23063: ruby:3.3 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23062

4 месяца назад

ELSA-2025-23062: ruby:3.3 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-j4pr-3wm6-xx2r

URI Credential Leakage Bypass over CVE-2025-27221

0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions prior to 0.12.5, 0.13.3, and 1.0.4, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the `+` operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. Versions 0.12.5, 0.13.3, and 1.0.4 fix the issue.

CVSS3: 7.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions prior to 0.12.5, 0.13.3, and 1.0.4, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the `+` operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. Versions 0.12.5, 0.13.3, and 1.0.4 fix the issue.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions prior to 0.12.5, 0.13.3, and 1.0.4, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the `+` operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. Versions 0.12.5, 0.13.3, and 1.0.4 fix the issue.

CVSS3: 7.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-61594

URI Credential Leakage Bypass over CVE-2025-27221

0%
Низкий
3 месяца назад
debian логотип
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifie ...

CVSS3: 7.5
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2025:23141

Moderate: ruby security update

3 месяца назад
rocky логотип
RLSA-2025:23063

Moderate: ruby:3.3 security update

3 месяца назад
rocky логотип
RLSA-2025:23062

Moderate: ruby:3.3 security update

3 месяца назад
oracle-oval логотип
ELSA-2025-23141

ELSA-2025-23141: ruby security update (MODERATE)

4 месяца назад
oracle-oval логотип
ELSA-2025-23063

ELSA-2025-23063: ruby:3.3 security update (MODERATE)

4 месяца назад
oracle-oval логотип
ELSA-2025-23062

ELSA-2025-23062: ruby:3.3 security update (MODERATE)

4 месяца назад

Уязвимостей на страницу