sinatra does not validate expanded path matches
Published: May 03, 2022
SECURITY IDENTIFIERS
- CVE: CVE-2022-29970 (NVD)
- GHSA: GHSA-qp49-3pvw-x4m5
- Vendor Advisory: https://github.com/sinatra/sinatra/pull/1683
GEM
SEVERITY
PATCHED VERSIONS
>= 2.2.0
DESCRIPTION
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
