Sinatra vulnerable to Reflected File Download attack
Package
Affected versions
>= 3.0, < 3.0.4
>= 2.0.0, < 2.2.3
Patched versions
3.0.4
2.2.3
Description
Published by the National Vulnerability Database
Nov 28, 2022
Published to the GitHub Advisory Database
Nov 30, 2022
Reviewed
Nov 30, 2022
Last updated
Feb 3, 2023
Description
An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input.
References
References