CVE-2018-11627
Summary
| CVE | CVE-2018-11627 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-31 19:29:00 UTC |
| Updated | 2019-02-26 15:03:00 UTC |
| Description | Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| XSS from params parser exception (status code : 400) · Issue #1428 · sinatra/sinatra · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| escape invalid query params, fixes #1428 · sinatra/sinatra@1278686 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690598 Free Berkeley Software Distribution (FreeBSD) Security Update for sinatra (ca05d9da-ac1d-4113-8a05-ffe9cd0d6160)