cbcvebase.
CVE-2025-27221
published 2025-03-04

CVE-2025-27221: In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because…

PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.47%
38.2th percentile
In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianruby2.7< ruby2.7 2.7.4-1+deb11u5 (bullseye)ruby2.7 2.7.4-1+deb11u5 (bullseye)
debianruby2.7
debianruby3.1< ruby2.7 2.7.4-1+deb11u5 (bullseye)ruby2.7 2.7.4-1+deb11u5 (bullseye)
debianruby3.1
debianruby3.3< ruby2.7 2.7.4-1+deb11u5 (bullseye)ruby2.7 2.7.4-1+deb11u5 (bullseye)
debianruby3.3
debianrubygems< ruby2.7 2.7.4-1+deb11u5 (bullseye)ruby2.7 2.7.4-1+deb11u5 (bullseye)
debianrubygems
msrcazl3_ruby_3.3.5-3_on_azure_linux_3.0
msrcazl3_ruby_3.3.5-6_on_azure_linux_3.0
msrcazl3_ruby_3.3.5-7_on_azure_linux_3.0
msrccbl2_ruby_3.1.4-9_on_cbl_mariner_2.0
msrccbl2_ruby_3.1.7-3_on_cbl_mariner_2.0
msrccbl2_ruby_3.1.7-4_on_cbl_mariner_2.0
ruby-languri< 0.11.30.11.3
ruby-languri< 0.12.50.12.5
ruby-languri>= 0 < 0.11.30.11.3
ruby-languri>= 0 < 0.12.50.12.5
ruby-languri>= 0.12.0 < 0.12.40.12.4
ruby-languri>= 0.12.0 < 0.12.40.12.4
ruby-languri>= 0.13.0 < 0.13.20.13.2
ruby-languri>= 0.13.0 < 0.13.30.13.3
ruby-languri>= 0.13.0 < 0.13.20.13.2
ruby-languri>= 0.13.0 < 0.13.30.13.3
ruby-languri>= 1.0.0 < 1.0.31.0.3

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ghsa5.3MEDIUM
osv6.6MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian3.2LOW
vendor_msrc3.2LOW
vendor_redhat3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.