XSS via the 400 Bad Request page
Published: May 31, 2018
SECURITY IDENTIFIERS
- CVE: CVE-2018-11627 (NVD)
- GHSA: GHSA-mq35-wqvf-r23c
- Vendor Advisory: https://github.com/sinatra/sinatra/issues/1428
GEM
SEVERITY
CVSS v3.x: 6.1 (Medium)
UNAFFECTED VERSIONS
< 2.0.0.beta1
= 2.0.0-alpha
PATCHED VERSIONS
>= 2.0.2
DESCRIPTION
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
