Known vulnerabilities in ruby2.5-rubygem-rack-doc-1_6
Vendor:
SUSE
Software:
ruby2.5-rubygem-rack-doc-1_6
Software CPE:
cpe:2.3:o:suse:ruby2_5-rubygem-rack-doc-1_6:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU105796 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-27610 |
CWE-22 | Medium | 1.6.8-150000.3.3.1 | 17.03.2025 |
SB2025031756 SB20250317118 SB20250317119 and 15 more |
||
| #VU105795 - Improper Output Neutralization for Logs CVE-2025-27111 |
CWE-117 | Medium | 1.6.8-150000.3.6.1 | 17.03.2025 |
SB2025031755 SB20250317119 SB2025031840 and 10 more |
||
| #VU105794 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2025-25184 |
CWE-93 | Low | 1.6.8-150000.3.3.1 | 17.03.2025 |
SB2025031754 SB2025031758 SB20250317118 and 8 more |