Skip to content

Commit 39fc4e5

Browse files
flavorjonesRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@a1c6e7c
1 parent 7512e1a commit 39fc4e5

10 files changed

Lines changed: 12 additions & 51 deletions

advisories/_posts/2023-10-30-CVE-2023-5349.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ advisory:
2020
- ">= 5.3.0"
2121
related:
2222
ghsa:
23-
- https://github.com/advisories/GHSA-j6x7-7g72-8ww2
23+
- j6x7-7g72-8ww2
2424
url:
2525
- https://nvd.nist.gov/vuln/detail/CVE-2023-5349
2626
- https://github.com/rmagick/rmagick/issues/1401

advisories/_posts/2024-03-21-CVE-2024-27281.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,5 +39,5 @@ advisory:
3939
patched_versions:
4040
- "~> 6.3.4, >= 6.3.4.1"
4141
- "~> 6.4.1, >= 6.4.1.1"
42-
- ">= 6.5.1.1"
42+
- ">= 6.5.1.1"
4343
---

advisories/_posts/2024-04-26-CVE-2024-32887.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ categories:
77
advisory:
88
gem: sidekiq
99
cve: 2024-32887
10-
ghsa: GHSA-q655-3pj8-9fxq
10+
ghsa: q655-3pj8-9fxq
1111
url: https://github.com/sidekiq/sidekiq/security/advisories/GHSA-q655-3pj8-9fxq
1212
title: Reflected XSS in Metrics Web Page
1313
date: 2024-04-26

advisories/_posts/2024-07-16-CVE-2024-39908.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ advisory:
3939
- ">= 3.3.2"
4040
related:
4141
ghsa:
42-
- https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh
42+
- vg3r-rm7w-2xgh
4343
url:
4444
- https://www.ruby-lang.org/en/news/2024/07/16/dos-rexml-cve-2024-39908
4545
- https://github.com/ruby/rexml/security/advisories/GHSA-4xqq-m2hx-25v8

advisories/_posts/2024-09-11-CVE-2024-45409.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -27,9 +27,8 @@ advisory:
2727
- ">= 2.2.1"
2828
related:
2929
ghsa:
30-
- https://github.com/omniauth/omniauth-saml/security/advisories/GHSA-cvp8-5r8g-fhvq
31-
- https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2
32-
- https://github.com/advisories/GHSA-cvp8-5r8g-fhvq
30+
- cvp8-5r8g-fhvq
31+
- jw9c-mfg7-9rx2
3332
url:
3433
- https://github.com/omniauth/omniauth-saml/commit/4274e9d57e65f2dcaae4aa3b2accf831494f2ddd
3534
- https://github.com/omniauth/omniauth-saml/commit/6c681fd082ab3daf271821897a40ab3417382e29

advisories/_posts/2025-03-14-GHSA-mrxw-mxhj-p664.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,6 @@ advisory:
4747
- https://gitlab.gnome.org/GNOME/libxslt/-/issues/128
4848
- https://github.com/advisories/GHSA-mrxw-mxhj-p664
4949
cve:
50-
- https://nvd.nist.gov/vuln/detail/CVE-2024-55549
51-
- https://nvd.nist.gov/vuln/detail/CVE-2025-24855
50+
- 2024-55549
51+
- 2025-24855
5252
---

advisories/_posts/2025-04-21-GHSA-5w6v-399v-w3cc.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -57,8 +57,8 @@ advisory:
5757
- ">= 1.18.8"
5858
related:
5959
cve:
60-
- CVE-2025-32414
61-
- CVE-2025-32415
60+
- 2025-32414
61+
- 2025-32415
6262
url:
6363
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-5w6v-399v-w3cc
6464
- https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.13.8

advisories/_posts/2025-05-08-CVE-2025-32441.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ advisory:
5454
- ">= 2.2.14"
5555
related:
5656
ghsa:
57-
- https://github.com/rack/rack-session/security/advisories/GHSA-9j94-67jr-4cqj
57+
- 9j94-67jr-4cqj
5858
url:
5959
- https://nvd.nist.gov/vuln/detail/CVE-2025-32441
6060
- https://github.com/rack/rack/security/advisories/GHSA-vpfw-47h7-xj4g

advisories/_posts/2025-05-08-CVE-2025-46336.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ advisory:
5656
- ">= 2.1.1"
5757
related:
5858
ghsa:
59-
- https://github.com/rack/rack/security/advisories/GHSA-vpfw-47h7-xj4g
59+
- vpfw-47h7-xj4g
6060
url:
6161
- https://nvd.nist.gov/vuln/detail/CVE-2025-46336
6262
- https://github.com/rack/rack-session/commit/c28c4a8c1861d814e09f2ae48264ac4c40be2d3b

advisories/_posts/2025-12-23-CVE-2025-68696.md

Lines changed: 0 additions & 38 deletions
Original file line numberDiff line numberDiff line change
@@ -62,44 +62,6 @@ advisory:
6262
Also, Python's `urljoin` function has documented a warning about similar behavior:
6363
<https://docs.python.org/3.13/library/urllib.parse.html#urllib.parse.urljoin>
6464
65-
## PoC
66-
67-
Follow these steps to reproduce the issue:
68-
69-
1. Set up two simple HTTP servers.
70-
71-
```bash
72-
mkdir /tmp/server1 /tmp/server2
73-
echo "this is server1" > /tmp/server1/index.html
74-
echo "this is server2" > /tmp/server2/index.html
75-
python -m http.server -d /tmp/server1 10001 &
76-
python -m http.server -d /tmp/server2 10002 &
77-
```
78-
79-
2. Create a script (for example, `main.rb`):
80-
81-
```rb
82-
require 'httparty'
83-
84-
class Client
85-
include HTTParty
86-
base_uri 'http://localhost:10001'
87-
end
88-
89-
data = Client.get('http://localhost:10002').body
90-
puts data
91-
```
92-
93-
3. Run the script:
94-
95-
```bash
96-
$ ruby main.rb
97-
this is server2
98-
```
99-
100-
Although `base_uri` is set to `http://localhost:10001/`, httparty sends the request to `http://localhost:10002/`.
101-
102-
10365
## Impact
10466
10567
- Leakage of credentials: If an absolute URL is provided, any API keys or credentials configured in httparty may be exposed to unintended third-party hosts.

0 commit comments

Comments
 (0)