In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 04 Mar 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | uri: userinfo leakage in URI#join, URI#merge and URI#+ | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 04 Mar 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-212 | |
Metrics |
cvssV3_1
|
Tue, 04 Mar 2025 00:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-03T00:00:00.000Z
Updated: 2025-03-04T16:39:00.368Z
Reserved: 2025-02-20T00:00:00.000Z
Link: CVE-2025-27221

Updated: 2025-03-04T16:38:53.645Z

Status : Received
Published: 2025-03-04T00:15:31.847
Modified: 2025-03-04T00:15:31.847
Link: CVE-2025-27221
