Количество 15
Количество 15
BDU:2026-06689
Уязвимость модуля URI языка программирования Ruby, системы управления пакетами RubyGems, позволяющая нарушителю получить доступ к конфиденциальным данным
ROS-20260512-73-0033
Уязвимость ruby
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4.
CVE-2025-61594
URI Credential Leakage Bypass over CVE-2025-27221
CVE-2025-61594
URI is a module providing classes to handle Uniform Resource Identifie ...
GHSA-j4pr-3wm6-xx2r
URI Credential Leakage Bypass over CVE-2025-27221
RLSA-2025:23141
Moderate: ruby security update
RLSA-2025:23063
Moderate: ruby:3.3 security update
RLSA-2025:23062
Moderate: ruby:3.3 security update
ELSA-2025-23141
ELSA-2025-23141: ruby security update (MODERATE)
ELSA-2025-23063
ELSA-2025-23063: ruby:3.3 security update (MODERATE)
ELSA-2025-23062
ELSA-2025-23062: ruby:3.3 security update (MODERATE)
SUSE-SU-2026:3090-1
Security update for ruby3.4
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-06689 Уязвимость модуля URI языка программирования Ruby, системы управления пакетами RubyGems, позволяющая нарушителю получить доступ к конфиденциальным данным | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
ROS-20260512-73-0033 Уязвимость ruby | 1% Низкий | 3 месяца назад | ||
CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4. | CVSS3: 7.5 | 1% Низкий | 7 месяцев назад | |
CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4. | CVSS3: 6.5 | 1% Низкий | 7 месяцев назад | |
CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifiers. In versions 0.12.4 and earlier (bundled in Ruby 3.2 series) 0.13.2 and earlier (bundled in Ruby 3.3 series), 1.0.3 and earlier (bundled in Ruby 3.4 series), when using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. This is a a bypass for the fix to CVE-2025-27221 that can expose user credentials. This issue has been fixed in versions 0.12.5, 0.13.3 and 1.0.4. | CVSS3: 7.5 | 1% Низкий | 7 месяцев назад | |
CVE-2025-61594 URI Credential Leakage Bypass over CVE-2025-27221 | 1% Низкий | 7 месяцев назад | ||
CVE-2025-61594 URI is a module providing classes to handle Uniform Resource Identifie ... | CVSS3: 7.5 | 1% Низкий | 7 месяцев назад | |
GHSA-j4pr-3wm6-xx2r URI Credential Leakage Bypass over CVE-2025-27221 | CVSS3: 7.5 | 1% Низкий | 7 месяцев назад | |
RLSA-2025:23141 Moderate: ruby security update | 7 месяцев назад | |||
RLSA-2025:23063 Moderate: ruby:3.3 security update | 7 месяцев назад | |||
RLSA-2025:23062 Moderate: ruby:3.3 security update | 7 месяцев назад | |||
ELSA-2025-23141 ELSA-2025-23141: ruby security update (MODERATE) | 8 месяцев назад | |||
ELSA-2025-23063 ELSA-2025-23063: ruby:3.3 security update (MODERATE) | 8 месяцев назад | |||
ELSA-2025-23062 ELSA-2025-23062: ruby:3.3 security update (MODERATE) | 8 месяцев назад | |||
SUSE-SU-2026:3090-1 Security update for ruby3.4 | 17 дней назад |
Уязвимостей на страницу