Vulnerabilities (CVE)

Filtered by vendor Sinatrarb Subscribe
Filtered by product Sinatra
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-29970 1 Sinatrarb 1 Sinatra 2022-05-09 5.0 MEDIUM 7.5 HIGH
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.