We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 152f634 commit 9fd379bCopy full SHA for 9fd379b
gems/sinatra/CVE-2024-21510.yml
@@ -4,7 +4,7 @@ cve: 2024-21510
4
ghsa: hxx2-7vcw-mqr3
5
url: https://github.com/advisories/GHSA-hxx2-7vcw-mqr3
6
title: Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
7
-date: 2024-11-01
+date: 2024-11-19
8
description: |
9
Versions of the package sinatra from 0.0.0 are vulnerable to
10
Reliance on Untrusted Inputs in a Security Decision via the
@@ -17,7 +17,8 @@ description: |
17
handling the X-Forwarded-Host header, attackers can potentially
18
exploit Cache Poisoning or Routing-based SSRF.
19
cvss_v3: 5.4
20
-notes: Never patched
+patched_versions:
21
+ - ">= 4.1.0"
22
related:
23
url:
24
- https://nvd.nist.gov/vuln/detail/CVE-2024-21510
0 commit comments