Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade pcs-snmpUpgrade pcs | Feb 22, 2023 | Nov 28, 2022 |
| Centos_linux | — | Upgrade pcsUpgrade pcs-snmp | Feb 22, 2023 | Nov 28, 2022 |
| Debian | — | Upgrade ruby-sinatra | Jan 12, 2023 | Nov 28, 2022 |
| Oracle_linux | — | Upgrade pcsUpgrade pcs-snmp | Feb 23, 2023 | Nov 28, 2022 |
| Redhat_linux | — | Upgrade pcsUpgrade pcs-snmp | Jan 27, 2023 | Nov 28, 2022 |
| Rocky_linux | — | Upgrade pcsUpgrade pcs-snmp | Mar 12, 2024 | Nov 28, 2022 |
| Ubuntu | — | Upgrade ruby-sinatra (Ubuntu Pro)Upgrade ruby-sinatra | Jun 26, 2025 | Nov 28, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub