Опубликовано: 02 мая 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5
Описание
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needed |
devel | not-affected | 3.0.5-3 |
esm-apps/bionic | released | 1.4.8-1ubuntu0.1~esm2 |
esm-apps/focal | released | 2.0.8.1-1ubuntu0.1~esm2 |
esm-apps/jammy | released | 2.0.8.1-2+deb11u1build0.22.04.1 |
esm-apps/xenial | released | 1.4.7-3ubuntu0.1~esm2 |
focal | ignored | end of standard support, was needed |
impish | ignored | end of life |
jammy | released | 2.0.8.1-2+deb11u1build0.22.04.1 |
kinetic | not-affected | 2.2.2-1 |
Показывать по
10
EPSS
Процентиль: 66%
0.00526
Низкий
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
redhat
больше 3 лет назад
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
CVSS3: 7.5
nvd
больше 3 лет назад
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
CVSS3: 7.5
debian
больше 3 лет назад
Sinatra before 2.2.0 does not validate that the expanded path matches ...
CVSS3: 7.5
github
больше 3 лет назад
sinatra does not validate expanded path matches
EPSS
Процентиль: 66%
0.00526
Низкий
5 Medium
CVSS2
7.5 High
CVSS3