Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2024-21510
Disclosure Date: November 01, 2024 (last updated November 01, 2024)
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.
0
Attacker Value
Unknown
CVE-2024-37116
Disclosure Date: July 22, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sinatrateam Sinatra allows Stored XSS.This issue affects Sinatra: from n/a through 1.3.
0
Attacker Value
Unknown
CVE-2022-45442
Disclosure Date: November 28, 2022 (last updated October 08, 2023)
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.
0
Attacker Value
Unknown
CVE-2022-29970
Disclosure Date: May 02, 2022 (last updated November 29, 2024)
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
0
Attacker Value
Unknown
CVE-2022-25209
Disclosure Date: February 15, 2022 (last updated October 25, 2023)
Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
0
Attacker Value
Unknown
CVE-2022-25208
Disclosure Date: February 15, 2022 (last updated October 25, 2023)
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
0
Attacker Value
Unknown
CVE-2022-25207
Disclosure Date: February 15, 2022 (last updated October 25, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
0
Attacker Value
Unknown
CVE-2019-1003086
Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
0
Attacker Value
Unknown
CVE-2019-1003087
Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
0
Attacker Value
Unknown
CVE-2018-11627
Disclosure Date: May 31, 2018 (last updated November 26, 2024)
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
0