Описание
ELSA-2023-12150: pcs security update (MODERATE)
[0.11.3-4.el9_1.2]
- Updated bundled rubygems: mustermann, rack, rack_protection, sinatra, tilt
- Added license for rubygem ruby2_keywords
- Resolves: rhbz#2159426
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
pcs
0.11.3-4.el9_1.2
pcs-snmp
0.11.3-4.el9_1.2
Oracle Linux x86_64
pcs
0.11.3-4.el9_1.2
pcs-snmp
0.11.3-4.el9_1.2
Связанные CVE
Связанные уязвимости
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.
Sinatra is a domain-specific language for creating web applications in ...
Sinatra vulnerable to Reflected File Download attack