CVE-2022-45442
published 2022-11-28CVE-2022-45442: Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An…
PriorityP340high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.64%
47.0th percentile
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ruby-sinatra | < ruby-sinatra 3.0.5-2 (bookworm) | ruby-sinatra 3.0.5-2 (bookworm) |
| sinatra | sinatra | — | — |
| sinatra | sinatra | — | — |
| sinatra | sinatra | >= 2.0.0 < 2.2.3 | 2.2.3 |
| sinatra | sinatra | >= 3.0 < 3.0.4 | 3.0.4 |
| sinatrarb | sinatra | >= 2.0.0 < 2.2.3 | 2.2.3 |
| sinatrarb | sinatra | >= 3.0.0 < 3.0.4 | 3.0.4 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ruby-sinatra vulnerabilities
osv·2025-07-22·CVSS 7.5
CVE-2022-29970 [HIGH] ruby-sinatra vulnerabilities
ruby-sinatra vulnerabilities
It was discovered that Sinatra incorrectly handled serving static files.
An attacker could possibly use this issue to perform local file inclusion,
obtaining sensitive information.
(CVE-2022-29970)
It was discovered that Sinatra incorrectly handled special characters in
the Content-Disposition HTTP header. An attacker could possibly use this
issue to perform a reflected file download attack, achieving remote code
execution. (CVE-2022-45442)
GHSA
Sinatra vulnerable to Reflected File Download attack
ghsa·2022-11-30
CVE-2022-45442 [HIGH] CWE-494 Sinatra vulnerable to Reflected File Download attack
Sinatra vulnerable to Reflected File Download attack
### Description
An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input.
### References
* https://www.blackhat.com/docs/eu-14/materials/eu-14-Hafif-Reflected-File-Download-A-New-Web-Attack-Vector.pdf
* https://github.com/advisories/GHSA-8x94-hmjh-97hq
OSV
Sinatra vulnerable to Reflected File Download attack
osv·2022-11-30
CVE-2022-45442 [HIGH] Sinatra vulnerable to Reflected File Download attack
Sinatra vulnerable to Reflected File Download attack
### Description
An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input.
### References
* https://www.blackhat.com/docs/eu-14/materials/eu-14-Hafif-Reflected-File-Download-A-New-Web-Attack-Vector.pdf
* https://github.com/advisories/GHSA-8x94-hmjh-97hq
OSV
CVE-2022-45442: Sinatra is a domain-specific language for creating web applications in Ruby
osv·2022-11-28·CVSS 8.8
CVE-2022-45442 [HIGH] CVE-2022-45442: Sinatra is a domain-specific language for creating web applications in Ruby
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.
Ubuntu
Sinatra vulnerabilities
vendor_ubuntu·2025-07-22·CVSS 7.5
CVE-2022-45442 [HIGH] Sinatra vulnerabilities
Title: Sinatra vulnerabilities
Summary: Several security issues were fixed in Sinatra.
It was discovered that Sinatra incorrectly handled serving static files.
An attacker could possibly use this issue to perform local file inclusion,
obtaining sensitive information.
(CVE-2022-29970)
It was discovered that Sinatra incorrectly handled special characters in
the Content-Disposition HTTP header. An attacker could possibly use this
issue to perform a reflected file download attack, achieving remote code
execution. (CVE-2022-45442)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
sinatra: Reflected File Download attack
vendor_redhat·2022-11-28·CVSS 8.8
CVE-2022-45442 [HIGH] CWE-494 sinatra: Reflected File Download attack
sinatra: Reflected File Download attack
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.
A flaw was found in Sinatra, a domain-specific language for creating web applications in Ruby. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input.
Package: 3scale-amp-backend-container (Red Hat 3scale API Management Platform 2) - Affected
Debian
CVE-2022-45442: ruby-sinatra - Sinatra is a domain-specific language for creating web applications in Ruby. An ...
vendor_debian·2022·CVSS 8.8
CVE-2022-45442 [HIGH] CVE-2022-45442: ruby-sinatra - Sinatra is a domain-specific language for creating web applications in Ruby. An ...
Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue.
Scope: local
bookworm: resolved (fixed in 3.0.5-2)
bullseye: resolved (fixed in 2.0.8.1-2+deb11u1)
forky: resolved (fixed in 3.0.5-2)
sid: resolved (fixed in 3.0.5-2)
trixie: resolved (fixed in 3.0.5-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/advisories/GHSA-8x94-hmjh-97hqhttps://github.com/sinatra/sinatra/commit/ea8fc9495a350f7551b39e3025bfcd06f49f363bhttps://github.com/sinatra/sinatra/security/advisories/GHSA-2x8x-jmrp-phxwhttps://lists.debian.org/debian-lts-announce/2023/01/msg00005.htmlhttps://www.blackhat.com/docs/eu-14/materials/eu-14-Hafif-Reflected-File-Download-A-New-Web-Attack-Vector.pdfhttps://github.com/advisories/GHSA-8x94-hmjh-97hqhttps://github.com/sinatra/sinatra/commit/ea8fc9495a350f7551b39e3025bfcd06f49f363bhttps://github.com/sinatra/sinatra/security/advisories/GHSA-2x8x-jmrp-phxwhttps://lists.debian.org/debian-lts-announce/2023/01/msg00005.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00020.htmlhttps://www.blackhat.com/docs/eu-14/materials/eu-14-Hafif-Reflected-File-Download-A-New-Web-Attack-Vector.pdf
2022-11-28
Published