Package | ruby-sinatra |
---|---|
Version | 1.4.7-5+deb9u1 (stretch) |
Related CVEs | CVE-2022-29970 |
A file traversal vulnerability was discovered in ruby-sinatra
, a popular web
server often used with Ruby on Rails. We now validate that any expanded paths
match the allowed public_dir
when serving static files.
For Debian 9 stretch, these problems have been fixed in version 1.4.7-5+deb9u1.
We recommend that you upgrade your ruby-sinatra packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.