VDB

CISA-2025-27221

CISA-2025-27221 PUBLISHED CVSS 3.2 LOW

Reported by mitre · Published March 3, 2025

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

Risk Scores

CVSS 3.1
3.2
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N

Affected Products

VendorProductVersions
ruby-langURI0, 0.12.0, 0.13.0
ruby-languri1.0.0, 0, 0.12.0
ruby-langURI0.12.0, 1.0.0, 0

Timeline

  • Mar 3, 2025 CVE Published
  • Nov 3, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›