Ruby/sinatra/2.2.0


Sinatra is a DSL for quickly creating web applications in Ruby with minimal effort.

https://rubygems.org/gems/sinatra
MIT

1 Security Vulnerabilities

Sinatra vulnerable to Reflected File Download attack

Published date: 2022-11-30T21:18:34Z
CVE: CVE-2022-45442
Links:

Description

An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input.

References

Affected versions: ["2.1.0", "2.0.8.1", "2.0.8", "2.0.7", "2.0.6", "2.0.5", "2.0.4", "2.0.3", "2.0.2", "2.0.1", "2.0.1.rc1", "2.0.0", "2.2.0", "2.2.1", "2.2.2", "3.0.0", "3.0.1", "3.0.2", "3.0.3"]
Secure versions: [3.0.4, 2.2.3, 3.0.5, 2.2.4, 3.0.6, 3.1.0, 3.2.0, 4.0.0]
Recommendation: Update to version 4.0.0.

103 Other Versions

Version License Security Released
0.1.6 UNKNOWN 3 2009-07-25 - 17:52 almost 15 years
0.1.5 UNKNOWN 3 2009-07-25 - 17:52 almost 15 years
0.1.0 UNKNOWN 3 2009-07-25 - 17:52 almost 15 years