VDB
Sign up
HIGH8.8

GHSA-2x8x-jmrp-phxw

Sinatra vulnerable to Reflected File Download attack

Quick fix

GHSA-2x8x-jmrp-phxw — sinatra: upgrade to the fixed version with the command below.

bundle update sinatra

Details

### Description An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input.

### References * https://www.blackhat.com/docs/eu-14/materials/eu-14-Hafif-Reflected-File-Download-A-New-Web-Attack-Vector.pdf * https://github.com/advisories/GHSA-8x94-hmjh-97hq

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/sinatra
Introduced in: 3.0Fixed in: 3.0.4
Fixbundle update sinatra
RubyGems/sinatra
Introduced in: 2.0.0Fixed in: 2.2.3
Fixbundle update sinatra

References