Sinatrarb
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Sinatrarb product.
RSS Feeds for Sinatrarb security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Sinatrarb products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Sinatrarb Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 0 vulnerabilities in Sinatrarb. Sinatrarb did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 2 | 8.80 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 0 | 0.00 |
| 2018 | 2 | 6.00 |
It may take a day or so for new Sinatrarb vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Sinatrarb Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2022-45442 | Nov 28, 2022 |
Reflected File Delivery (RFD) in Sinatra <2.2.3 & <3.0.4Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. Version 2.2.3 and 3.0.4 contain patches for this issue. |
|
| CVE-2022-29970 | May 02, 2022 |
Sinatra before 2.2.0 does not validateSinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. |
|
| CVE-2018-11627 | May 31, 2018 |
Sinatra before 2.0.2 has XSS via the 400 Bad Request pageSinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. |
|
| CVE-2018-1000119 | Mar 07, 2018 |
Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checkingSinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and earlier contains a timing attack vulnerability in the CSRF token checking that can result in signatures can be exposed. This attack appear to be exploitable via network connectivity to the ruby application. This vulnerability appears to have been fixed in 1.5.5 and 2.0.0. |
|