PT-2025-40972 · Ruby+8 · Ruby+8
Chongfujun
+2
·
Published
2025-01-01
·
Updated
2026-05-12
·
CVE-2025-61594
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ruby versions prior to 3.4.7
Description
The URI gem contained a flaw that allowed for credential leakage, bypassing previous fixes. This issue impacts systems utilizing the URI gem and could potentially expose sensitive information.
Recommendations
Update to Ruby version 3.4.7 or later.
Update the uri gem to the latest version.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Ruby
Ubuntu