Vulnerability Details
Basic Information
| Title | Researchers Identify Rack::Static Vulnerability Enabling Data Breaches in Ruby Servers |
|---|---|
| Type | thn |
| Published | 2025-04-25T08:57:00 |
| Last Seen | 2025-04-25T10:54:50 |
| CVSS Score | 9.8 (CRITICAL) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2025-25184, CVE-2025-27111, CVE-2025-27610, CVE-2025-43928 |
|---|---|
| CWE | |
| Bulletin Family | info |
Description
Cybersecurity researchers have disclosed three security flaws in the Rack Ruby web server interface that, if successfully exploited, could enable attackers to gain unauthorized access to files, inject malicious data, and tamper with logs under…
Impact Assessment
| Base Score | 9.8 |
|---|---|
| Severity | CRITICAL |