File tree Expand file tree Collapse file tree 1 file changed +41
-0
lines changed Expand file tree Collapse file tree 1 file changed +41
-0
lines changed Original file line number Diff line number Diff line change 1+ ---
2+ gem : uri
3+ cve : 2025-61594
4+ url : https://www.ruby-lang.org/en/news/2025/10/07/uri-cve-2025-61594
5+ title : CVE-2025-61594 - URI Credential Leakage Bypass over CVE-2025-27221
6+ date : 2025-10-07
7+ description : |
8+
9+ In affected URI version, a bypass exists for the fix to CVE-2025-27221
10+ that can expose user credentials.
11+
12+ This vulnerability has been assigned the CVE identifier CVE-2025-61594.
13+ We recommend upgrading the uri gem.
14+
15+ ## Details
16+
17+ When using the + operator to combine URIs, sensitive information
18+ like passwords from the original URI can be leaked, violating
19+ RFC3986 and making applications vulnerable to credential exposure.
20+
21+ Please update URI gem to version 0.12.5, 0.13.3, 1.0.4 or later.
22+
23+ ## Affected versions
24+
25+ uri gem versions < 0.12.5, 0.13.0 to 0.13.2 and 1.0.0 to 1.0.3.
26+
27+ ## Credits
28+
29+ Thanks to junfuchong (chongfujun) for discovering this issue.
30+ Also thanks to nobu for additional fixes of this vulnerability.
31+ patched_versions :
32+ - " ~> 0.12.5"
33+ - " ~> 0.13.3"
34+ - " >= 1.0.4"
35+ related :
36+ url :
37+ - https://www.ruby-lang.org/en/news/2025/10/07/uri-cve-2025-61594
38+ - https://rubygems.org/gems/uri/versions/1.0.4
39+ - https://rubygems.org/gems/uri/versions/0.13.3
40+ - https://rubygems.org/gems/uri/versions/0.12.5
41+ - https://github.com/ruby/uri
You can’t perform that action at this time.
0 commit comments