Логотип exploitDog
bind:"CVE-2024-21510"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-21510"

Количество 8

Количество 8

ubuntu логотип

CVE-2024-21510

8 месяцев назад

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2024-21510

8 месяцев назад

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-21510

8 месяцев назад

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-21510

8 месяцев назад

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance ...

CVSS3: 5.4
EPSS: Низкий
redos логотип

ROS-20250326-04

3 месяца назад

Уязвимость rubygem-sinatra

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-hxx2-7vcw-mqr3

8 месяцев назад

Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision

CVSS3: 5.4
EPSS: Низкий
oracle-oval логотип

ELSA-2024-10987

6 месяцев назад

ELSA-2024-10987: pcs security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-03808

около 1 года назад

Уязвимость фреймворка разработки веб-приложений на Ruby Sinatra, связанная с ошибками при обработке входных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-21510

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
redhat логотип
CVE-2024-21510

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2024-21510

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
debian логотип
CVE-2024-21510

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance ...

CVSS3: 5.4
0%
Низкий
8 месяцев назад
redos логотип
ROS-20250326-04

Уязвимость rubygem-sinatra

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-hxx2-7vcw-mqr3

Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision

CVSS3: 5.4
0%
Низкий
8 месяцев назад
oracle-oval логотип
ELSA-2024-10987

ELSA-2024-10987: pcs security update (MODERATE)

6 месяцев назад
fstec логотип
BDU:2025-03808

Уязвимость фреймворка разработки веб-приложений на Ruby Sinatra, связанная с ошибками при обработке входных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 5.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу