PT-2025-8696 · Ruby+9 · Uri+9

Lambdasawa

+1

·

Published

2025-02-26

·

Updated

2026-01-03

·

CVE-2025-27221

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions URI gem versions prior to 0.11.3 URI gem versions 0.12.0 through 0.12.3 URI gem versions 0.13.0 through 0.13.1 URI gem versions 1.0.0 through 1.0.2
Description The URI handling methods (URI.join, URI#merge, URI#+) in the URI gem for Ruby have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host. This could lead to an unintended userinfo leak when generating a URL to a malicious host from a URL containing secret userinfo using these methods.
Recommendations For URI gem versions prior to 0.11.3, update to version 0.11.3 or later. For URI gem versions 0.12.0 through 0.12.3, update to version 0.12.4 or later. For URI gem versions 0.13.0 through 0.13.1, update to version 0.13.2 or later. For URI gem versions 1.0.0 through 1.0.2, update to version 1.0.3 or later. As a temporary workaround, consider avoiding the use of URI#join, URI#merge, and URI#+ methods until a patch is available.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALSA-2025:10217
ALSA-2025:4063
ALSA-2025:4488
ALSA-2025:8131
ALSA-2025_10217
ALSA-2025_4488
AZL-57778
AZL-57893
BDU:2025-05129
CESA-2025_10217
CESA-2025_4063
CVE-2025-27221
DLA-4082-1
DLA-4163-1
ECHO-0F02-8857-9466
GHSA-22H5-PQ3X-2GF2
INFSA-2025_10217
INFSA-2025_4063
INFSA-2025_4488
INFSA-2025_4493
MGASA-2025-0290
OESA-2025-1244
OESA-2025-1261
OESA-2025-1262
OESA-2025-1263
OESA-2025-1264
RHSA-2025:10217
RHSA-2025:4063
RHSA-2025:4488
RHSA-2025:4493
RHSA-2025:8131
RHSA-2025_10217
RHSA-2025_4063
RHSA-2025_4488
RHSA-2025_4493
SUSE-SU-2025:02739-1
SUSE-SU-2025:02739-2
SUSE-SU-2025:4264-1
SUSE-SU-2025_02739-1
SUSE-SU-2025_02739-2
USN-7418-1
USN-7442-1

Affected Products

Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Uri
Ubuntu