Количество 35
Количество 35
CVE-2025-58767
REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 h ...
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.
CVE-2025-61594
URI Credential Leakage Bypass over CVE-2025-27221
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifie ...
ROS-20251111-05
Уязвимость rubygem-rexml
GHSA-c2f4-jgmc-q2r5
REXML has DoS condition when parsing malformed XML file
ROS-20260512-80-0042
Уязвимость ruby
GHSA-j4pr-3wm6-xx2r
URI Credential Leakage Bypass over CVE-2025-27221
BDU:2026-06689
Уязвимость модуля URI языка программирования Ruby, системы управления пакетами RubyGems, позволяющая нарушителю получить доступ к конфиденциальным данным
SUSE-SU-2025:4264-1
Security update for ruby2.5
ROS-20260512-73-0033
Уязвимость ruby
SUSE-SU-2026:1066-1
Security update for ruby2.5
SUSE-SU-2026:3090-1
Security update for ruby3.4
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-58767 REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 h ... | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4. | CVSS3: 7.5 | 1% Низкий | 9 месяцев назад | |
CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4. | CVSS3: 6.5 | 1% Низкий | 9 месяцев назад | |
CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4. | CVSS3: 7.5 | 1% Низкий | 9 месяцев назад | |
CVE-2025-61594 URI Credential Leakage Bypass over CVE-2025-27221 | 1% Низкий | 9 месяцев назад | ||
CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifie ... | CVSS3: 7.5 | 1% Низкий | 9 месяцев назад | |
ROS-20251111-05 Уязвимость rubygem-rexml | CVSS3: 5.3 | 0% Низкий | 11 месяцев назад | |
GHSA-c2f4-jgmc-q2r5 REXML has DoS condition when parsing malformed XML file | 0% Низкий | около 1 года назад | ||
ROS-20260512-80-0042 Уязвимость ruby | 1% Низкий | 5 месяцев назад | ||
GHSA-j4pr-3wm6-xx2r URI Credential Leakage Bypass over CVE-2025-27221 | CVSS3: 7.5 | 1% Низкий | 9 месяцев назад | |
BDU:2026-06689 Уязвимость модуля URI языка программирования Ruby, системы управления пакетами RubyGems, позволяющая нарушителю получить доступ к конфиденциальным данным | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
SUSE-SU-2025:4264-1 Security update for ruby2.5 | 10 месяцев назад | |||
ROS-20260512-73-0033 Уязвимость ruby | 1% Низкий | 5 месяцев назад | ||
SUSE-SU-2026:1066-1 Security update for ruby2.5 | 6 месяцев назад | |||
SUSE-SU-2026:3090-1 Security update for ruby3.4 | 2 месяца назад |
Уязвимостей на страницу