CVE-2025-27221
CVE-2025-27221
Título es
CVE-2025-27221
Mar, 04/03/2025 – 00:15
Tipo
CWE-212
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-27221
Descripción en
In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.
04/03/2025
04/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
3.20
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
LOW
Referencias
https://github.com/rubysec/ruby-advisory-db/blob/master/gems/uri/CVE-2025-27221.yml
https://hackerone.com/reports/2957667
Enviar en el boletín
Off