Количество 33
Количество 33
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.
CVE-2025-61594
URI Credential Leakage Bypass over CVE-2025-27221
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifie ...
ROS-20251111-05
Уязвимость rubygem-rexml
GHSA-c2f4-jgmc-q2r5
REXML has DoS condition when parsing malformed XML file
GHSA-j4pr-3wm6-xx2r
URI Credential Leakage Bypass over CVE-2025-27221
BDU:2026-06689
Уязвимость модуля URI языка программирования Ruby, системы управления пакетами RubyGems, позволяющая нарушителю получить доступ к конфиденциальным данным
SUSE-SU-2025:4264-1
Security update for ruby2.5
ROS-20260512-73-0033
Уязвимость ruby
SUSE-SU-2026:1066-1
Security update for ruby2.5
SUSE-SU-2026:3090-1
Security update for ruby3.4
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4. | CVSS3: 7.5 | 1% Низкий | 7 месяцев назад | |
CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4. | CVSS3: 6.5 | 1% Низкий | 7 месяцев назад | |
CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4. | CVSS3: 7.5 | 1% Низкий | 7 месяцев назад | |
CVE-2025-61594 URI Credential Leakage Bypass over CVE-2025-27221 | 1% Низкий | 7 месяцев назад | ||
CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifie ... | CVSS3: 7.5 | 1% Низкий | 7 месяцев назад | |
ROS-20251111-05 Уязвимость rubygem-rexml | CVSS3: 5.3 | 0% Низкий | 9 месяцев назад | |
GHSA-c2f4-jgmc-q2r5 REXML has DoS condition when parsing malformed XML file | 0% Низкий | 11 месяцев назад | ||
GHSA-j4pr-3wm6-xx2r URI Credential Leakage Bypass over CVE-2025-27221 | CVSS3: 7.5 | 1% Низкий | 7 месяцев назад | |
BDU:2026-06689 Уязвимость модуля URI языка программирования Ruby, системы управления пакетами RubyGems, позволяющая нарушителю получить доступ к конфиденциальным данным | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
SUSE-SU-2025:4264-1 Security update for ruby2.5 | 8 месяцев назад | |||
ROS-20260512-73-0033 Уязвимость ruby | 1% Низкий | 3 месяца назад | ||
SUSE-SU-2026:1066-1 Security update for ruby2.5 | 4 месяца назад | |||
SUSE-SU-2026:3090-1 Security update for ruby3.4 | 17 дней назад |
Уязвимостей на страницу