CVE-2022-29970
Summary
| CVE | CVE-2022-29970 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-02 05:15:00 UTC |
| Updated | 2022-11-16 17:12:00 UTC |
| Description | Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3166-1] ruby-sinatra security update |
MLIST |
lists.debian.org |
|
| Validate expanded path matches public_dir when serving static files by cji-stripe · Pull Request #1683 · sinatra/sinatra · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159847 Oracle Enterprise Linux Security Update for pcs (ELSA-2022-9416)
- 159922 Oracle Enterprise Linux Security Update for pcs (ELSA-2022-9513)
- 181171 Debian Security Update for ruby-sinatra (DLA 3166-1)
- 182827 Debian Security Update for ruby-sinatra (CVE-2022-29970)
- 240340 Red Hat Update for pcs (RHSA-2022:2256)
- 240341 Red Hat Update for pcs (RHSA-2022:2253)
- 240346 Red Hat Update for pcs (RHSA-2022:4587)
- 240357 Red Hat Update for pcs (RHSA-2022:4661)
- 240925 Red Hat Update for Satellite 6.12 (RHSA-2022:8506)
- 940580 AlmaLinux Security Update for pcs (ALSA-2022:4661)
- 940636 AlmaLinux Security Update for pcs (ALSA-2022:4587)
- 960147 Rocky Linux Security Update for pcs (RLSA-2022:4661)
- 960485 Rocky Linux Security Update for Satellite (RLSA-2022:8506)