HIGH7.5
GHSA-qp49-3pvw-x4m5
sinatra does not validate expanded path matches
Quick fix
GHSA-qp49-3pvw-x4m5 — sinatra: upgrade to the fixed version with the command below.
bundle update sinatraDetails
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-29970[ADVISORY]
- https://github.com/sinatra/sinatra/pull/1683[WEB]
- https://github.com/sinatra/sinatra/pull/1683/commits/462c3ca1db53ed3cfc394cf5948e9c948ad1c10e[WEB]
- https://github.com/skylightio/skylight-ruby/pull/294[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sinatra/CVE-2022-29970.yml[WEB]
- https://github.com/sinatra/sinatra[WEB]
- https://lists.debian.org/debian-lts-announce/2022/10/msg00034.html[WEB]
- https://lists.debian.org/debian-lts-announce/2024/09/msg00020.html[WEB]