Red Hat Bugzilla – Bug 1585218
CVE-2018-11627 rubygem-sinatra: XSS in the 400 Bad Request page
Last modified: 2018-06-29 18:38:40 EDT
It was found that Sinatra is vulnerable to an XSS via the 400 Bad Request page that occurs upon a params parser exception. Upstream issue: https://github.com/sinatra/sinatra/issues/1428 Introduced by: https://github.com/sinatra/sinatra/commit/8f8df53ff29938ace79b31097c27d9cdac803b44 Upstream patch: https://github.com/sinatra/sinatra/commit/12786867d6faaceaec62c7c2cb5b0e2dc074d71a
Created rubygem-sinatra tracking bugs for this issue: Affects: fedora-all [bug 1585221]