Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-12137

Опубликовано: 22 фев. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-12137: pcs security update (MODERATE)

[0.10.14-5.0.1]

  • Replace HAM-logo.png with a generic one

[0.10.14-5.el8_7.2]

  • Updated bundled rubygems: mustermann, rack, rack_protection, sinatra, tilt
  • Added license for rubygem ruby2_keywords
  • Resolves: rhbz#2159424

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

pcs

0.10.14-5.0.1.el8_7.2

pcs-snmp

0.10.14-5.0.1.el8_7.2

Oracle Linux x86_64

pcs

0.10.14-5.0.1.el8_7.2

pcs-snmp

0.10.14-5.0.1.el8_7.2

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 3 года назад

Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.

CVSS3: 8.8
redhat
почти 3 года назад

Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.

CVSS3: 8.8
nvd
почти 3 года назад

Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.

CVSS3: 8.8
debian
почти 3 года назад

Sinatra is a domain-specific language for creating web applications in ...

CVSS3: 8.8
github
почти 3 года назад

Sinatra vulnerable to Reflected File Download attack