VDB
Sign up
MEDIUM6.1

GHSA-mq35-wqvf-r23c

Sinatra Cross-site Scripting vulnerability

Quick fix

GHSA-mq35-wqvf-r23c — sinatra: upgrade to the fixed version with the command below.

bundle update sinatra

Details

Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/sinatra
Introduced in: 2.0.0Fixed in: 2.0.2
Fixbundle update sinatra

References