← Back to CVE List

CVE-2025-27221

Published: 2025-03-04T00:15Z
Last Modified: 2025-03-05T14:05Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt