/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-g9vr-7jx4-v7vv

Published

Last updated

https://images.chainguard.dev/security/CGA-g9vr-7jx4-v7vv
Package

ruby-3.0

RepositoryWolfi
Latest Update
Fix not planned
Aliases
  • CVE-2025-27221
  • GHSA-22h5-pq3x-2gf2

Severity

Unknown

Summary

URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+

Description

There is a possibility for userinfo leakage by in the uri gem. This vulnerability has been assigned the CVE identifier CVE-2025-27221. We recommend upgrading the uri gem.

Details

The methods URI#join, URI#merge, and URI#+ retained userinfo, such as user:password, even after the host is replaced. When generating a URL to a malicious host from a URL containing secret userinfo using these methods, and having someone access that URL, an unintended userinfo leak could occur.

Please update URI gem to version 0.11.3, 0.12.4, 0.13.2, 1.0.3 or later.

Affected versions

uri gem versions < 0.11.3, 0.12.0 to 0.12.3, 0.13.0, 0.13.1 and 1.0.0 to 1.0.2.

Credits

Thanks to Tsubasa Irisawa (lambdasawa) for discovering this issue. Also thanks to nobu for additional fixes of this vulnerability.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs