A ruby-sinatra security update has been released for Debian GNU/Linux 9 Extended LTS to address a vulnerability where a reflected file download (RFD) attack sets the Content-Disposition header of a response when the filename is derived from user-supplied input.
ELA-787-1 ruby-sinatra security update
Package : ruby-sinatra
ELA-787-1 ruby-sinatra security update
Version : 1.4.7-5+deb9u2 (stretch)
Related CVEs :
CVE-2022-45442
Sinatra is a domain-specific language for creating web applications in Ruby. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input.