Логотип exploitDog
bind:"BDU:2025-03808" OR bind:"CVE-2024-21510"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-03808" OR bind:"CVE-2024-21510"

Количество 8

Количество 8

fstec логотип

BDU:2025-03808

больше 1 года назад

Уязвимость фреймворка разработки веб-приложений на Ruby Sinatra, связанная с ошибками при обработке входных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2024-21510

около 1 года назад

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2024-21510

около 1 года назад

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-21510

около 1 года назад

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-21510

около 1 года назад

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance ...

CVSS3: 5.4
EPSS: Низкий
redos логотип

ROS-20250326-04

8 месяцев назад

Уязвимость rubygem-sinatra

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-hxx2-7vcw-mqr3

около 1 года назад

Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision

CVSS3: 5.4
EPSS: Низкий
oracle-oval логотип

ELSA-2024-10987

11 месяцев назад

ELSA-2024-10987: pcs security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-03808

Уязвимость фреймворка разработки веб-приложений на Ruby Sinatra, связанная с ошибками при обработке входных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 5.4
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-21510

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-21510

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-21510

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-21510

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance ...

CVSS3: 5.4
0%
Низкий
около 1 года назад
redos логотип
ROS-20250326-04

Уязвимость rubygem-sinatra

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-hxx2-7vcw-mqr3

Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision

CVSS3: 5.4
0%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2024-10987

ELSA-2024-10987: pcs security update (MODERATE)

11 месяцев назад

Уязвимостей на страницу