Количество 38
Количество 38
CVE-2025-27221
In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.
CVE-2025-27221
In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.jo ...
CVE-2025-27219
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.
CVE-2025-27219
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.
CVE-2025-27219
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.
CVE-2025-27219
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.
CVE-2025-27219
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in ...
GHSA-22h5-pq3x-2gf2
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
BDU:2025-05129
Уязвимость программного средства URI gem, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальной информации
GHSA-gh9q-2xrm-x6qv
CGI has Denial of Service (DoS) potential in Cookie.parse
BDU:2025-05128
Уязвимость программного средства cgi gem, связанная с неправильная проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании
SUSE-SU-2025:02739-2
Security update for ruby2.5
SUSE-SU-2025:02739-1
Security update for ruby2.5
ROS-20250417-13
Уязвимость ruby
RLSA-2025:4487
Moderate: ruby security update
ELSA-2025-4487
ELSA-2025-4487: ruby security update (MODERATE)
SUSE-SU-2025:1369-1
Security update for ruby2.5
ROS-20250417-12
Множественные уязвимости ruby
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-27221 In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host. | CVSS3: 3.2 | 0% Низкий | больше 1 года назад | |
CVE-2025-27221 In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.jo ... | CVSS3: 3.2 | 0% Низкий | больше 1 года назад | |
CVE-2025-27219 In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies. | CVSS3: 5.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-27219 In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies. | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
CVE-2025-27219 In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies. | CVSS3: 5.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-27219 In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies. | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
CVE-2025-27219 In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in ... | CVSS3: 5.8 | 1% Низкий | больше 1 года назад | |
GHSA-22h5-pq3x-2gf2 URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+ | CVSS3: 3.2 | 0% Низкий | больше 1 года назад | |
BDU:2025-05129 Уязвимость программного средства URI gem, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальной информации | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-gh9q-2xrm-x6qv CGI has Denial of Service (DoS) potential in Cookie.parse | CVSS3: 5.8 | 1% Низкий | больше 1 года назад | |
BDU:2025-05128 Уязвимость программного средства cgi gem, связанная с неправильная проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
SUSE-SU-2025:02739-2 Security update for ruby2.5 | 11 месяцев назад | |||
SUSE-SU-2025:02739-1 Security update for ruby2.5 | 12 месяцев назад | |||
ROS-20250417-13 Уязвимость ruby | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
RLSA-2025:4487 Moderate: ruby security update | около 1 года назад | |||
ELSA-2025-4487 ELSA-2025-4487: ruby security update (MODERATE) | около 1 года назад | |||
SUSE-SU-2025:1369-1 Security update for ruby2.5 | больше 1 года назад | |||
ROS-20250417-12 Множественные уязвимости ruby | CVSS3: 7.5 | больше 1 года назад |
Уязвимостей на страницу