MEDIUM6.1
GHSA-mq35-wqvf-r23c
Sinatra Cross-site Scripting vulnerability
Quick fix
GHSA-mq35-wqvf-r23c — sinatra: upgrade to the fixed version with the command below.
bundle update sinatraDetails
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-11627[ADVISORY]
- https://github.com/sinatra/sinatra/issues/1428[WEB]
- https://github.com/sinatra/sinatra/commit/12786867d6faaceaec62c7c2cb5b0e2dc074d71a[WEB]
- https://access.redhat.com/errata/RHSA-2019:0212[WEB]
- https://access.redhat.com/errata/RHSA-2019:0315[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sinatra/CVE-2018-11627.yml[WEB]
- https://github.com/sinatra/sinatra[PACKAGE]