VDB
Sign up
MEDIUM5.3

GHSA-h29f-7f56-j8wh

Sinatra Path Traversal vulnerability

Quick fix

GHSA-h29f-7f56-j8wh — sinatra: upgrade to the fixed version with the command below.

bundle update sinatra

Details

An issue was discovered in `rack-protection/lib/rack/protection/path_traversal.rb` in Sinatra 2.x before 2.0.1 on Windows. Path traversal is possible via backslash characters.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/sinatra
Introduced in: 2.0.0.beta1Fixed in: 2.0.1
Fixbundle update sinatra

References