Skip to content

Update uri gem to resolve security vulnerability#11945

Merged
mitchellhenke merged 1 commit intomainfrom
mitchellhenke/update-uri
Mar 5, 2025
Merged

Update uri gem to resolve security vulnerability#11945
mitchellhenke merged 1 commit intomainfrom
mitchellhenke/update-uri

Conversation

@mitchellhenke
Copy link
Contributor

🛠 Summary of changes

Addresses CVE-2025-27221

Name: uri
Version: 1.0.2
CVE: CVE-2025-27221
GHSA: GHSA-22h5-pq3x-2gf2
Criticality: Low
URL: https://www.cve.org/CVERecord?id=CVE-2025-27221
Title: CVE-2025-27221 - userinfo leakage in URI#join, URI#merge and URI#+.
Solution: update to '~> 0.11.3', '~> 0.12.4', '~> 0.13.2', '>= 1.0.3'

changelog: Internal, Maintenance, Update uri gem to resolve security vulnerability
@mitchellhenke mitchellhenke force-pushed the mitchellhenke/update-uri branch 2 times, most recently from 5d914fe to 29cffa8 Compare March 5, 2025 14:19
@mitchellhenke mitchellhenke requested a review from a team March 5, 2025 14:52
@mitchellhenke mitchellhenke merged commit 6df0d27 into main Mar 5, 2025
2 checks passed
@mitchellhenke mitchellhenke deleted the mitchellhenke/update-uri branch March 5, 2025 14:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants