CVE-2022-45442: Sinatra vulnerable to Reflected File Download attack
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sinatrato a version that resolves this vulnerability.Fixed in 2.2.3 - Upgrade
Upgrade
Sinatrato a version that resolves this vulnerability.Fixed in 3.0.4
Event History
Frequently Asked Questions
What is Sinatra?
Sinatra is a domain-specific language for creating web applications in Ruby.
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-45442.
What is the severity of CVE-2022-45442?
The severity of CVE-2022-45442 is high with a CVSS score of 8.8.
What is the affected software?
The affected software is Sinatra versions 2.0 before 2.2.3 and 3.0 before 3.0.4, as well as Debian Linux version 10.0.
How can I fix the vulnerability in Sinatra?
To fix the vulnerability in Sinatra, upgrade to version 2.2.3 or 3.0.4.