Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-29970

Опубликовано: 02 мая 2022
Источник: redhat
CVSS3: 7.5

Описание

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

A flaw was found in Sinatra when serving static files from the public directory. The requested path is not validated if it is in the public directory, allowing files outside of the public directory to be served.

Меры по смягчению последствий

Disable the static option which will disable the public_dir option. With this configuration, Sinatra will not serve files from the public directory and therefore files outside of it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7pcsAffected
Red Hat Satellite 6tfm-ror51-rubygem-mustermannAffected
Red Hat Satellite 6tfm-ror51-rubygem-rack-protectionAffected
Red Hat Satellite 6tfm-ror51-rubygem-sinatraAffected
Red Hat Satellite 6tfm-ror52-rubygem-mustermannAffected
Red Hat Satellite 6tfm-ror52-rubygem-rack-protectionAffected
Red Hat Satellite 6tfm-ror52-rubygem-sinatraAffected
Red Hat Satellite 6tfm-rubygem-mustermannAffected
Red Hat Satellite 6tfm-rubygem-rack-protectionAffected
Red Hat Satellite 6tfm-rubygem-sinatraAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2081096sinatra: path traversal possible outside of public_dir when serving static files

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

CVSS3: 7.5
nvd
почти 4 года назад

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

CVSS3: 7.5
debian
почти 4 года назад

Sinatra before 2.2.0 does not validate that the expanded path matches ...

CVSS3: 7.5
github
почти 4 года назад

sinatra does not validate expanded path matches

oracle-oval
больше 3 лет назад

ELSA-2022-9513: pcs security update (IMPORTANT)

7.5 High

CVSS3