⚠ This page is served via a proxy. Original site: https://github.com
This service does not collect credentials or authentication data.
Skip to content

Commit 71a4127

Browse files
jasnowpostmodern
authored andcommitted
GHSA SYNC: Added cvss_v3 field/value to 1 advisory
1 parent 81853a7 commit 71a4127

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

gems/httparty/CVE-2025-68696.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -98,6 +98,7 @@ description: |
9898
- Leakage of credentials: If an absolute URL is provided, any API keys or credentials configured in httparty may be exposed to unintended third-party hosts.
9999
- SSRF (Server-Side Request Forgery): Attackers can force the httparty-based program to send requests to other internal hosts within the network where the program is running.
100100
- Affected users: Any software that uses `base_uri` and does not properly validate the path parameter may be affected by this issue.
101+
cvss_v3: 8.2
101102
cvss_v4: 8.8
102103
patched_versions:
103104
- ">= 0.24.0"

0 commit comments

Comments
 (0)