A flaw was found in rack-protection. Versions prior to 2.0.0.rc3 of the package are vulnerable to Timing Attack due to time-variable comparison of signatures. A malicious user can guess a valid signature one char at a time by considering the time it takes a signature validation to fail.
References: https://snyk.io/vuln/SNYK-RUBY-SINATRA-20470 https://snyk.io/vuln/SNYK-RUBY-RACKPROTECTION-20395
Patch: https://github.com/sinatra/sinatra/commit/8aa6c42ef724f93ae309fb7c5668e19ad547eceb