CVE-2022-29970

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
5
MEDIUM
Affected
1
PROJECT

Description

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

Classy web-development dressed in a DSL (official / canonical repo)
GitHubGitHub
12.4K