CVE-2022-45442
Summary
| CVE | CVE-2022-45442 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-28 21:15:00 UTC |
| Updated | 2023-02-01 15:47:00 UTC |
| Description | Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Sinatra vulnerable to Reflected File Download attack · Advisory · sinatra/sinatra · GitHub |
CONFIRM |
github.com |
|
| Django 3.2 before 3.2.15 and 4.0 before 4.0.7 vulnerable to Reflected File Download attack · CVE-2022-36359 · GitHub Advisory Database · GitHub |
MISC |
github.com |
|
| escape filename in the Content-Disposition header · sinatra/sinatra@ea8fc94 · GitHub |
MISC |
github.com |
|
| [SECURITY] [DLA 3264-1] ruby-sinatra security update |
MLIST |
lists.debian.org |
|
| www.blackhat.com/docs/eu-14/materials/eu-14-Hafif-Reflected-File-Download-A-Ne... |
MISC |
www.blackhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160474 Oracle Enterprise Linux Security Update for pcs (ELSA-2023-12137)
- 160493 Oracle Enterprise Linux Security Update for pcs (ELSA-2023-12150)
- 181463 Debian Security Update for ruby-sinatra (DLA 3264-1)
- 182966 Debian Security Update for ruby-sinatra (CVE-2022-45442)
- 241129 Red Hat Update for pcs (RHSA-2023:0427)
- 241146 Red Hat Update for pcs (RHSA-2023:0527)
- 241148 Red Hat Update for pcs (RHSA-2023:0506)
- 241206 Red Hat Update for pcs (RHSA-2023:0855)
- 241225 Red Hat Update for pcs (RHSA-2023:0974)
- 241612 Red Hat Update for pcs (RHSA-2023:0393)
- 241659 Red Hat Update for pcs (RHSA-2023:0857)
- 940933 AlmaLinux Security Update for pcs (ALSA-2023:0855)
- 940951 AlmaLinux Security Update for pcs (ALSA-2023:0974)
- 960662 Rocky Linux Security Update for pcs (RLSA-2023:0855)