Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-29970

Опубликовано: 02 мая 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

A flaw was found in Sinatra when serving static files from the public directory. The requested path is not validated if it is in the public directory, allowing files outside of the public directory to be served.

Меры по смягчению последствий

Disable the static option which will disable the public_dir option. With this configuration, Sinatra will not serve files from the public directory and therefore files outside of it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7pcsAffected
Red Hat Satellite 6tfm-ror51-rubygem-mustermannAffected
Red Hat Satellite 6tfm-ror51-rubygem-rack-protectionAffected
Red Hat Satellite 6tfm-ror51-rubygem-sinatraAffected
Red Hat Satellite 6tfm-ror52-rubygem-mustermannAffected
Red Hat Satellite 6tfm-ror52-rubygem-rack-protectionAffected
Red Hat Satellite 6tfm-ror52-rubygem-sinatraAffected
Red Hat Satellite 6tfm-rubygem-mustermannAffected
Red Hat Satellite 6tfm-rubygem-rack-protectionAffected
Red Hat Satellite 6tfm-rubygem-sinatraAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2081096sinatra: path traversal possible outside of public_dir when serving static files

EPSS

Процентиль: 66%
0.00526
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

CVSS3: 7.5
nvd
больше 3 лет назад

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

CVSS3: 7.5
debian
больше 3 лет назад

Sinatra before 2.2.0 does not validate that the expanded path matches ...

CVSS3: 7.5
github
больше 3 лет назад

sinatra does not validate expanded path matches

oracle-oval
около 3 лет назад

ELSA-2022-9513: pcs security update (IMPORTANT)

EPSS

Процентиль: 66%
0.00526
Низкий

7.5 High

CVSS3