Skip to content

Commit 8bb632a

Browse files
jasnowRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@71a4127
1 parent 310bc9e commit 8bb632a

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

advisories/_posts/2025-12-23-CVE-2025-68696.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -105,6 +105,7 @@ advisory:
105105
- Leakage of credentials: If an absolute URL is provided, any API keys or credentials configured in httparty may be exposed to unintended third-party hosts.
106106
- SSRF (Server-Side Request Forgery): Attackers can force the httparty-based program to send requests to other internal hosts within the network where the program is running.
107107
- Affected users: Any software that uses `base_uri` and does not properly validate the path parameter may be affected by this issue.
108+
cvss_v3: 8.2
108109
cvss_v4: 8.8
109110
patched_versions:
110111
- ">= 0.24.0"

0 commit comments

Comments
 (0)