cbcvebase.
CVE-2018-11627
published 2018-05-31

CVE-2018-11627: Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.

medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianruby-sinatra
redhatcloudforms
redhatcloudforms
sinatrasinatra>= 2.0.0 < 2.0.22.0.2
sinatrarbsinatra< 2.0.22.0.2

CVSS provenance

nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM