Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 33

Количество 33

ubuntu логотип

CVE-2025-61594

7 месяцев назад

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-61594

7 месяцев назад

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-61594

7 месяцев назад

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-61594

7 месяцев назад

URI Credential Leakage Bypass over CVE-2025-27221

EPSS: Низкий
debian логотип

CVE-2025-61594

7 месяцев назад

URI is a module providing classes to handle Uniform Resource Identifie ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20251111-05

9 месяцев назад

Уязвимость rubygem-rexml

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-c2f4-jgmc-q2r5

11 месяцев назад

REXML has DoS condition when parsing malformed XML file

EPSS: Низкий
github логотип

GHSA-j4pr-3wm6-xx2r

7 месяцев назад

URI Credential Leakage Bypass over CVE-2025-27221

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-06689

около 1 года назад

Уязвимость модуля URI языка программирования Ruby, системы управления пакетами RubyGems, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4264-1

8 месяцев назад

Security update for ruby2.5

EPSS: Низкий
redos логотип

ROS-20260512-73-0033

3 месяца назад

Уязвимость ruby

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1066-1

4 месяца назад

Security update for ruby2.5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3090-1

17 дней назад

Security update for ruby3.4

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.

CVSS3: 7.5
1%
Низкий
7 месяцев назад
redhat логотип
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.

CVSS3: 6.5
1%
Низкий
7 месяцев назад
nvd логотип
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.

CVSS3: 7.5
1%
Низкий
7 месяцев назад
msrc логотип
CVE-2025-61594

URI Credential Leakage Bypass over CVE-2025-27221

1%
Низкий
7 месяцев назад
debian логотип
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifie ...

CVSS3: 7.5
1%
Низкий
7 месяцев назад
redos логотип
ROS-20251111-05

Уязвимость rubygem-rexml

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-c2f4-jgmc-q2r5

REXML has DoS condition when parsing malformed XML file

0%
Низкий
11 месяцев назад
github логотип
GHSA-j4pr-3wm6-xx2r

URI Credential Leakage Bypass over CVE-2025-27221

CVSS3: 7.5
1%
Низкий
7 месяцев назад
fstec логотип
BDU:2026-06689

Уязвимость модуля URI языка программирования Ruby, системы управления пакетами RubyGems, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 7.5
1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:4264-1

Security update for ruby2.5

8 месяцев назад
redos логотип
ROS-20260512-73-0033

Уязвимость ruby

1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1066-1

Security update for ruby2.5

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3090-1

Security update for ruby3.4

17 дней назад

Уязвимостей на страницу