Debian 10225 Published by

A ruby-sinatra security update has been released for Debian GNU/Linux 9 Extended LTS to address a vulnerability where a reflected file download (RFD) attack sets the Content-Disposition header of a response when the filename is derived from user-supplied input.



ELA-787-1 ruby-sinatra security update

Package : ruby-sinatra
Version : 1.4.7-5+deb9u2 (stretch)

Related CVEs :
CVE-2022-45442

Sinatra is a domain-specific language for creating web applications in Ruby. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input.

  ELA-787-1 ruby-sinatra security update