Jnunemaker Httparty vulnerabilities
3 known vulnerabilities affecting jnunemaker/httparty.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-68696HIGHCVSS 8.8fixed in 0.24.0≤ 0.23.22025-12-23
CVE-2025-68696 [HIGH] CWE-918 CVE-2025-68696: httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue ca
httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. This issue has been patched via commit 0529bcd.
cvelistv5ghsanvdosv
CVE-2024-22049MEDIUMCVSS 5.3fixed in 0.21.02024-01-04
CVE-2024-22049 [MEDIUM] CWE-472 CVE-2024-22049: httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote a
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.
ghsanvdosv
CVE-2013-1801HIGHCVSS 7.5≤ 0.9.0v0.1.0+44 more2013-04-09
CVE-2013-1801 [HIGH] CVE-2013-1801: The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156.
ghsanvdosv