Path traversal is possible via backslash characters on Windows.
Published: February 18, 2018
SECURITY IDENTIFIERS
- CVE: CVE-2018-7212 (NVD)
- Vendor Advisory: https://github.com/sinatra/sinatra/pull/1379
GEM
PATCHED VERSIONS
>= 2.0.1
~> 1.5.4
DESCRIPTION
An issue was discovered in rack-protection 2.x before 2.0.1 on Windows. Path traversal is possible via backslash characters.
