First published: Sun Feb 18 2018(Updated: )
An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows. Path traversal is possible via backslash characters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sinatrarb Sinatra | =2.0.0 | |
Sinatrarb Sinatra | =2.0.0-beta2 | |
Sinatrarb Sinatra | =2.0.0-rc1 | |
Sinatrarb Sinatra | =2.0.0-rc2 | |
Sinatrarb Sinatra | =2.0.0-rc3 | |
Sinatrarb Sinatra | =2.0.0-rc4 | |
Sinatrarb Sinatra | =2.0.0-rc5 | |
Sinatrarb Sinatra | =2.0.0-rc6 | |
Sinatrarb Sinatra | =2.0.1-rc1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7212 is a vulnerability in Sinatra 2.x before 2.0.1 on Windows that allows path traversal via backslash characters.
CVE-2018-7212 has a severity score of 5.3, which is classified as medium.
To exploit CVE-2018-7212, an attacker can use backslash characters to traverse directories and access sensitive files on a Windows system.
Yes, Sinatra 2.x versions including 2.0.0, 2.0.0-beta2, 2.0.0-rc1, 2.0.0-rc2, 2.0.0-rc3, 2.0.0-rc4, 2.0.0-rc5, 2.0.0-rc6, and 2.0.1-rc1 are affected by CVE-2018-7212.
To fix CVE-2018-7212, upgrade to Sinatra version 2.0.1 or later.