Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-pcsalma-upgrade-pcs-snmp | Feb 22, 2023 | Nov 28, 2022 | |
| Centos_linux | — | centos-upgrade-pcscentos-upgrade-pcs-snmp | Feb 22, 2023 | Nov 28, 2022 |
| Debian | debian-upgrade-ruby-sinatra | Jan 12, 2023 | Nov 28, 2022 | |
| Oracle_linux | — | oracle-linux-upgrade-pcsoracle-linux-upgrade-pcs-snmp | Feb 23, 2023 | Nov 28, 2022 |
| Redhat_linux | redhat-upgrade-pcsredhat-upgrade-pcs-snmp | Jan 27, 2023 | Nov 28, 2022 | |
| Rocky_linux | rocky-upgrade-pcsrocky-upgrade-pcs-snmp | Mar 12, 2024 | Nov 28, 2022 | |
| Ubuntu | ubuntu-pro-upgrade-ruby-sinatraubuntu-upgrade-ruby-sinatra | Jun 26, 2025 | Nov 28, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub