Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2024-21510

Disclosure Date: November 01, 2024 (last updated November 01, 2024)
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.
0
Attacker Value
Unknown

CVE-2024-37116

Disclosure Date: July 22, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sinatrateam Sinatra allows Stored XSS.This issue affects Sinatra: from n/a through 1.3.
Attacker Value
Unknown

CVE-2022-45442

Disclosure Date: November 28, 2022 (last updated October 08, 2023)
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.
Attacker Value
Unknown

CVE-2022-29970

Disclosure Date: May 02, 2022 (last updated November 29, 2024)
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
Attacker Value
Unknown

CVE-2022-25209

Disclosure Date: February 15, 2022 (last updated October 25, 2023)
Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Attacker Value
Unknown

CVE-2022-25208

Disclosure Date: February 15, 2022 (last updated October 25, 2023)
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
Attacker Value
Unknown

CVE-2022-25207

Disclosure Date: February 15, 2022 (last updated October 25, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
Attacker Value
Unknown

CVE-2019-1003086

Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
0
Attacker Value
Unknown

CVE-2019-1003087

Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
Attacker Value
Unknown

CVE-2018-11627

Disclosure Date: May 31, 2018 (last updated November 26, 2024)
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
0