CVE-2018-11627
published 2018-05-31CVE-2018-11627: Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
PriorityP425medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
2.21%
80.8th percentile
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ruby-sinatra | — | — |
| redhat | cloudforms | — | — |
| redhat | cloudforms | — | — |
| sinatra | sinatra | >= 2.0.0 < 2.0.2 | 2.0.2 |
| sinatrarb | sinatra | < 2.0.2 | 2.0.2 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-sinatra: XSS in the 400 Bad Request page
vendor_redhat·2018-05-22·CVSS 6.1
CVE-2018-11627 [MEDIUM] CWE-79 rubygem-sinatra: XSS in the 400 Bad Request page
rubygem-sinatra: XSS in the 400 Bad Request page
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
Package: rubygem-sinatra (Red Hat Ceph Storage 1.3) - Not affected
Package: pcs (Red Hat Enterprise Linux 6) - Not affected
Package: pcs (Red Hat Enterprise Linux 7) - Not affected
Package: pcs (Red Hat Enterprise Linux 8) - Not affected
Package: rubygem-sinatra (Red Hat Enterprise Linux 8) - Not affected
Package: rubygem-sinatra (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools) - Not affected
Package: rubygem-sinatra (Red Hat Enterprise MRG 2) - Not affected
Package: rubygem-sinatra (Red Hat OpenStack Platform 10 (Newton) Operational Tools) - Not affected
Package: rubygem-sinatra (Red Hat OpenStack Platform
Debian
CVE-2018-11627: ruby-sinatra - Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a par...
vendor_debian·2018·CVSS 6.1
CVE-2018-11627 [MEDIUM] CVE-2018-11627: ruby-sinatra - Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a par...
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
Sinatra Cross-site Scripting vulnerability
ghsa·2018-06-05
CVE-2018-11627 [MEDIUM] CWE-79 Sinatra Cross-site Scripting vulnerability
Sinatra Cross-site Scripting vulnerability
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
OSV
Sinatra Cross-site Scripting vulnerability
osv·2018-06-05
CVE-2018-11627 [MEDIUM] Sinatra Cross-site Scripting vulnerability
Sinatra Cross-site Scripting vulnerability
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
OSV
CVE-2018-11627: Sinatra before 2
osv·2018-05-31·CVSS 6.1
CVE-2018-11627 [MEDIUM] CVE-2018-11627: Sinatra before 2
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-11627 rubygem-sinatra: XSS in the 400 Bad Request page [fedora-all]
bugzilla·2018-06-01·CVSS 6.1
CVE-2018-11627 [MEDIUM] CVE-2018-11627 rubygem-sinatra: XSS in the 400 Bad Request page [fedora-all]
CVE-2018-11627 rubygem-sinatra: XSS in the 400 Bad Request page [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2018-11627 rubygem-sinatra: XSS in the 400 Bad Request page
bugzilla·2018-06-01·CVSS 6.1
CVE-2018-11627 [MEDIUM] CVE-2018-11627 rubygem-sinatra: XSS in the 400 Bad Request page
CVE-2018-11627 rubygem-sinatra: XSS in the 400 Bad Request page
It was found that Sinatra is vulnerable to an XSS via the 400 Bad Request page that occurs upon a params parser exception.
Upstream issue:
https://github.com/sinatra/sinatra/issues/1428
Introduced by:
https://github.com/sinatra/sinatra/commit/8f8df53ff29938ace79b31097c27d9cdac803b44
Upstream patch:
https://github.com/sinatra/sinatra/commit/12786867d6faaceaec62c7c2cb5b0e2dc074d71a
Discussion:
Created rubygem-sinatra tracking bugs for this issue:
Affects: fedora-all [bug 1585221]
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.10
Via RHSA-2019:0212 https://access.redhat.com/errata/RHSA-2019:0212
---
This issue has been addressed in the following products:
CloudForms Ma
https://access.redhat.com/errata/RHSA-2019:0212https://access.redhat.com/errata/RHSA-2019:0315https://github.com/sinatra/sinatra/commit/12786867d6faaceaec62c7c2cb5b0e2dc074d71ahttps://github.com/sinatra/sinatra/issues/1428https://access.redhat.com/errata/RHSA-2019:0212https://access.redhat.com/errata/RHSA-2019:0315https://github.com/sinatra/sinatra/commit/12786867d6faaceaec62c7c2cb5b0e2dc074d71ahttps://github.com/sinatra/sinatra/issues/1428
2018-05-31
Published