CVE-2022-29970
published 2022-05-02CVE-2022-29970: Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.18%
80.5th percentile
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ruby-sinatra | < ruby-sinatra 2.2.2-1 (bookworm) | ruby-sinatra 2.2.2-1 (bookworm) |
| sinatra | sinatra | >= 0 < 2.2.0 | 2.2.0 |
| sinatrarb | sinatra | < 2.2.0 | 2.2.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ruby-sinatra vulnerabilities
osv·2025-07-22·CVSS 7.5
CVE-2022-29970 [HIGH] ruby-sinatra vulnerabilities
ruby-sinatra vulnerabilities
It was discovered that Sinatra incorrectly handled serving static files.
An attacker could possibly use this issue to perform local file inclusion,
obtaining sensitive information.
(CVE-2022-29970)
It was discovered that Sinatra incorrectly handled special characters in
the Content-Disposition HTTP header. An attacker could possibly use this
issue to perform a reflected file download attack, achieving remote code
execution. (CVE-2022-45442)
GHSA
sinatra does not validate expanded path matches
ghsa·2022-05-03
CVE-2022-29970 [HIGH] CWE-22 sinatra does not validate expanded path matches
sinatra does not validate expanded path matches
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
OSV
sinatra does not validate expanded path matches
osv·2022-05-03
CVE-2022-29970 [HIGH] sinatra does not validate expanded path matches
sinatra does not validate expanded path matches
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
OSV
CVE-2022-29970: Sinatra before 2
osv·2022-05-02·CVSS 7.5
CVE-2022-29970 [HIGH] CVE-2022-29970: Sinatra before 2
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
Ubuntu
Sinatra vulnerabilities
vendor_ubuntu·2025-07-22·CVSS 7.5
CVE-2022-45442 [HIGH] Sinatra vulnerabilities
Title: Sinatra vulnerabilities
Summary: Several security issues were fixed in Sinatra.
It was discovered that Sinatra incorrectly handled serving static files.
An attacker could possibly use this issue to perform local file inclusion,
obtaining sensitive information.
(CVE-2022-29970)
It was discovered that Sinatra incorrectly handled special characters in
the Content-Disposition HTTP header. An attacker could possibly use this
issue to perform a reflected file download attack, achieving remote code
execution. (CVE-2022-45442)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
sinatra: path traversal possible outside of public_dir when serving static files
vendor_redhat·2022-05-02·CVSS 7.5
CVE-2022-29970 [HIGH] CWE-22 sinatra: path traversal possible outside of public_dir when serving static files
sinatra: path traversal possible outside of public_dir when serving static files
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
A flaw was found in Sinatra when serving static files from the public directory. The requested path is not validated if it is in the public directory, allowing files outside of the public directory to be served.
Mitigation: Disable the static option which will disable the public_dir option. With this configuration, Sinatra will not serve files from the public directory and therefore files outside of it.
Package: pcs (Red Hat Enterprise Linux 7) - Affected
Package: tfm-ror51-rubygem-mustermann (Red Hat Satellite 6) - Affected
Package: tfm-ror51-rubygem-rack-protection (Red Hat Satellite 6) - Affecte
Debian
CVE-2022-29970: ruby-sinatra - Sinatra before 2.2.0 does not validate that the expanded path matches public_dir...
vendor_debian·2022·CVSS 7.5
CVE-2022-29970 [HIGH] CVE-2022-29970: ruby-sinatra - Sinatra before 2.2.0 does not validate that the expanded path matches public_dir...
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
Scope: local
bookworm: resolved (fixed in 2.2.2-1)
bullseye: resolved (fixed in 2.0.8.1-2+deb11u1)
forky: resolved (fixed in 2.2.2-1)
sid: resolved (fixed in 2.2.2-1)
trixie: resolved (fixed in 2.2.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/sinatra/sinatra/pull/1683/commits/462c3ca1db53ed3cfc394cf5948e9c948ad1c10ehttps://lists.debian.org/debian-lts-announce/2022/10/msg00034.htmlhttps://github.com/sinatra/sinatra/pull/1683/commits/462c3ca1db53ed3cfc394cf5948e9c948ad1c10ehttps://lists.debian.org/debian-lts-announce/2022/10/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00020.html
2022-05-02
Published