Описание
Sinatra Cross-site Scripting vulnerability
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-11627
- https://github.com/sinatra/sinatra/issues/1428
- https://github.com/sinatra/sinatra/commit/12786867d6faaceaec62c7c2cb5b0e2dc074d71a
- https://access.redhat.com/errata/RHSA-2019:0212
- https://access.redhat.com/errata/RHSA-2019:0315
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sinatra/CVE-2018-11627.yml
Пакеты
Наименование
sinatra
rubygems
Затронутые версииВерсия исправления
>= 2.0.0, < 2.0.2
2.0.2
Связанные уязвимости
CVSS3: 6.1
ubuntu
больше 7 лет назад
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
CVSS3: 6.1
redhat
больше 7 лет назад
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
CVSS3: 6.1
nvd
больше 7 лет назад
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
CVSS3: 6.1
debian
больше 7 лет назад
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs ...