Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-12150

Опубликовано: 01 мар. 2023
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2023-12150: pcs security update (MODERATE)

[0.11.3-4.el9_1.2]

  • Updated bundled rubygems: mustermann, rack, rack_protection, sinatra, tilt
  • Added license for rubygem ruby2_keywords
  • Resolves: rhbz#2159426

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

pcs

0.11.3-4.el9_1.2

pcs-snmp

0.11.3-4.el9_1.2

Oracle Linux x86_64

pcs

0.11.3-4.el9_1.2

pcs-snmp

0.11.3-4.el9_1.2

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 3 года назад

Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.

CVSS3: 8.8
redhat
почти 3 года назад

Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.

CVSS3: 8.8
nvd
почти 3 года назад

Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.

CVSS3: 8.8
debian
почти 3 года назад

Sinatra is a domain-specific language for creating web applications in ...

CVSS3: 8.8
github
почти 3 года назад

Sinatra vulnerable to Reflected File Download attack