Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 15

Количество 15

fstec логотип

BDU:2026-06689

около 1 года назад

Уязвимость модуля URI языка программирования Ruby, системы управления пакетами RubyGems, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260512-73-0033

3 месяца назад

Уязвимость ruby

EPSS: Низкий
ubuntu логотип

CVE-2025-61594

7 месяцев назад

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-61594

7 месяцев назад

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-61594

7 месяцев назад

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-61594

7 месяцев назад

URI Credential Leakage Bypass over CVE-2025-27221

EPSS: Низкий
debian логотип

CVE-2025-61594

7 месяцев назад

URI is a module providing classes to handle Uniform Resource Identifie ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-j4pr-3wm6-xx2r

7 месяцев назад

URI Credential Leakage Bypass over CVE-2025-27221

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2025:23141

7 месяцев назад

Moderate: ruby security update

EPSS: Низкий
rocky логотип

RLSA-2025:23063

7 месяцев назад

Moderate: ruby:3.3 security update

EPSS: Низкий
rocky логотип

RLSA-2025:23062

7 месяцев назад

Moderate: ruby:3.3 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23141

8 месяцев назад

ELSA-2025-23141: ruby security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23063

8 месяцев назад

ELSA-2025-23063: ruby:3.3 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23062

8 месяцев назад

ELSA-2025-23062: ruby:3.3 security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3090-1

17 дней назад

Security update for ruby3.4

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-06689

Уязвимость модуля URI языка программирования Ruby, системы управления пакетами RubyGems, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 7.5
1%
Низкий
около 1 года назад
redos логотип
ROS-20260512-73-0033

Уязвимость ruby

1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.

CVSS3: 7.5
1%
Низкий
7 месяцев назад
redhat логотип
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.

CVSS3: 6.5
1%
Низкий
7 месяцев назад
nvd логотип
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.

CVSS3: 7.5
1%
Низкий
7 месяцев назад
msrc логотип
CVE-2025-61594

URI Credential Leakage Bypass over CVE-2025-27221

1%
Низкий
7 месяцев назад
debian логотип
CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifie ...

CVSS3: 7.5
1%
Низкий
7 месяцев назад
github логотип
GHSA-j4pr-3wm6-xx2r

URI Credential Leakage Bypass over CVE-2025-27221

CVSS3: 7.5
1%
Низкий
7 месяцев назад
rocky логотип
RLSA-2025:23141

Moderate: ruby security update

7 месяцев назад
rocky логотип
RLSA-2025:23063

Moderate: ruby:3.3 security update

7 месяцев назад
rocky логотип
RLSA-2025:23062

Moderate: ruby:3.3 security update

7 месяцев назад
oracle-oval логотип
ELSA-2025-23141

ELSA-2025-23141: ruby security update (MODERATE)

8 месяцев назад
oracle-oval логотип
ELSA-2025-23063

ELSA-2025-23063: ruby:3.3 security update (MODERATE)

8 месяцев назад
oracle-oval логотип
ELSA-2025-23062

ELSA-2025-23062: ruby:3.3 security update (MODERATE)

8 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3090-1

Security update for ruby3.4

17 дней назад

Уязвимостей на страницу