VYPR

rpm package

suse/ruby2.5&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS

pkg:rpm/suse/ruby2.5&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Vulnerabilities (7)

  • CVE-2025-6442MedJun 25, 2025
    affected < 2.5.9-150000.4.46.1fixed 2.5.9-150000.4.46.1

    Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specif

  • CVE-2025-27221LowMar 4, 2025
    affected < 2.5.9-150000.4.46.1fixed 2.5.9-150000.4.46.1

    In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

  • CVE-2025-27220MedMar 4, 2025
    affected < 2.5.9-150000.4.41.1fixed 2.5.9-150000.4.41.1

    In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

  • CVE-2025-27219MedMar 4, 2025
    affected < 2.5.9-150000.4.41.1fixed 2.5.9-150000.4.41.1

    In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource

  • CVE-2024-49761HigOct 28, 2024
    affected < 2.5.9-150000.4.36.1fixed 2.5.9-150000.4.36.1

    REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected mainta

  • CVE-2024-47220Sep 22, 2024
    affected < 2.5.9-150000.4.36.1fixed 2.5.9-150000.4.36.1

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2024-35221MedMay 29, 2024
    affected < 2.5.9-150000.4.49.1fixed 2.5.9-150000.4.49.1

    Rubygems.org is the Ruby community's gem hosting service. A Gem publisher can cause a Remote DoS when publishing a Gem. This is due to how Ruby reads the Manifest of Gem files when using Gem::Specification.from_yaml. from_yaml makes use of SafeYAML.load which allows YAML aliases