Sha256: 40aaf8bceaf9e00c3d046d2dbcca58d85132de32e8f62c8865d32792d04da7a9

Contents?: true

Size: 368 Bytes

Versions: 3

Compression:

Stored size: 368 Bytes

Contents

---
gem: sinatra
cve: 2018-11627
url: https://github.com/sinatra/sinatra/issues/1428
title: XSS via the 400 Bad Request page
date: 2018-05-31
description: |
  Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.

cvss_v3: 6.1

patched_versions:
  - ">= 2.0.2"
unaffected_versions:
  - "< 2.0.0.beta1"
  - "2.0.0-alpha"

Version data entries

3 entries across 3 versions & 2 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/sinatra/CVE-2018-11627.yml
bundler-budit-0.6.2 data/ruby-advisory-db/gems/sinatra/CVE-2018-11627.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/sinatra/CVE-2018-11627.yml