-
CVSS Score
-The vulnerability description explicitly identifies URI#join, URI#merge, and URI#+ as the affected methods. These are instance methods of the URI::Generic class in Ruby's URI gem, as confirmed by:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| uri | rubygems | < 0.11.3 | 0.11.3 |
| uri | rubygems | >= 0.12.0, < 0.12.4 | 0.12.4 |
| uri | rubygems | >= 0.13.0, < 0.13.2 | 0.13.2 |
| uri | rubygems | >= 1.0.0, < 1.0.3 | 1.0.3 |
A Semantic Attack on Google Gemini - Read the Latest Research