VDB
CVE-2025-55193
CVE-2025-55193
PUBLISHED
Ruby on Rails ist ein in der Programmiersprache Ruby geschriebenes und quelloffenes Web Application Framework.
EPSS 0.57% · 44.4th percentile
Risk Scores
EPSS Score
0.57%
44.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fedora | Fedora Linux | |
| Open Source | Open Source Ruby on Rails <8.0.2.1 | |
| Open Source | Open Source Ruby on Rails <7.1.5.2 | |
| SUSE | SUSE openSUSE | |
| Debian | Debian Linux | |
| IBM | IBM License Metric Tool | |
| Open Source | Open Source Ruby on Rails <7.2.2.2 |
Timeline
- Jan 21, 1970 Security Advisory
- Aug 13, 2025 CVE Published
- Aug 14, 2025 EPSS Score
- Aug 14, 2025 Coalition ESS Score
- Aug 14, 2025 Coalition ESS Score
- Aug 22, 2025 EPSS Score
- Aug 26, 2025 Coalition ESS Score
- Aug 31, 2025 EPSS Score
- Sep 8, 2025 EPSS Score
- Sep 17, 2025 EPSS Score
- Sep 25, 2025 EPSS Score
- Oct 3, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1822.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1822 advisory
- https://rubyonrails.org/2025/8/13/Rails-Versions-8-0-2-1-7-2-2-2-and-7-1-5-2-have-been-released advisory
- https://discuss.rubyonrails.org/t/cve-2025-24293-active-storage-allowed-transformation-methods-potentially-unsafe/89670 advisory
- https://github.com/advisories/GHSA-r4mg-4433-c7g3 advisory
- https://discuss.rubyonrails.org/t/cve-2025-55193-ansi-escape-injection-in-active-record-logging/89669 advisory
- https://github.com/advisories/GHSA-76r7-hhxj-r776 advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/EAQWF525THZXMYKQ2S2HIBKOWWDEAPW3/ advisory
- https://www.ibm.com/support/pages/node/7245706 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-6e5c27d218 advisory
- https://lists.debian.org/debian-security-announce/2025/msg00257.html advisory
- https://lists.debian.org/debian-lts-announce/2025/12/msg00032.html advisory