REDHAT-BUG-2323117: SSRF
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2323117?
The severity of REDHAT-BUG-2323117 is classified as critical due to the potential for Open Redirect Attacks.
How do I fix REDHAT-BUG-2323117?
To fix REDHAT-BUG-2323117, upgrade the Sinatra package to a version above 0.0.0 where the vulnerability is addressed.
What causes the vulnerability in REDHAT-BUG-2323117?
The vulnerability in REDHAT-BUG-2323117 arises from reliance on untrusted inputs in security decision-making related to the X-Forwarded-Host (XFH) header.
Which versions of Sinatra are affected by REDHAT-BUG-2323117?
All versions of the Sinatra package from 0.0.0 are affected by REDHAT-BUG-2323117.
Can REDHAT-BUG-2323117 be exploited remotely?
Yes, REDHAT-BUG-2323117 can be exploited remotely through crafted requests that manipulate the X-Forwarded-Host header.