#22245 closed enhancement (fixed)
ruby-3.4.7
| Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (5)
comment:1 by , 12 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 12 months ago
| Priority: | normal → elevated |
|---|
comment:3 by , 12 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at commits
00e1ef790e Update to unixODBC-2.3.14. effc98c679 Update to ruby-3.4.7 (Security update).
Note:
See TracTickets
for help on using tickets.

This is a security fix release for CVE-2025-61594 in the 'uri' gem that's bundled with Ruby. This is a credential leakage problem.
Details from the announcement of the security vulnerability upstream:
CVE-2025-61594: URI Credential Leakage Bypass over CVE-2025-27221 In affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. This vulnerability has been assigned the CVE identifier CVE-2025-61594. We recommend upgrading the uri gem. Details When using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. Please update URI gem to version 0.12.5, 0.13.3, 1.0.4 or later. Affected versions uri gem versions < 0.12.5, 0.13.0 to 0.13.2 and 1.0.0 to 1.0.3.The rest of the release notes are:
What's Changed Merge URI-1.0.4 for Ruby 3.4 by hsbt · Pull Request #14757 Bug #21313: it in rescue/ensure on prism - Ruby - Ruby Issue Tracking System [3.4] compile.c: Handle anonymous variables in outer_variable_cmp by byroot · Pull Request #13493 Bug #21610: Use ec->interrupt_mask to prevent interrupts. - Ruby - Ruby Issue Tracking System Bug #21611: Ruby 3.4.6 can't be built with GCC 15.2.1 - Ruby - Ruby Issue Tracking System Bug #21342: Segfault: invalid keeping_mutexes when using Mutex in Thread then Fiber after GC - Ruby - Ruby Issue Tracking System Bug #21569: [armv7, musl] SIGBUS in ibf_load_object_float due to unaligned VFP double load when reading IBF - Ruby - Ruby Issue Tracking System Bug #21568: Requiring core libraries when already requiring multiple user defined libraries with the same name can error - Ruby - Ruby Issue Tracking System