← Back

CVE-2018-7212

nvd nist
Published: Feb 18, 2018Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows. Path traversal is possible via backslash characters.

Affected (9)

Products: Sinatrarb: Sinatra
1 product
Sinatra
Configuration A
9 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Sinatrarb
Version 2.0.0
Version 2.0.0 beta2
Version 2.0.0 rc1
Version 2.0.0 rc2
Version 2.0.0 rc3
Version 2.0.0 rc4
Version 2.0.0 rc5
Version 2.0.0 rc6
Version 2.0.1 rc1
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (4)

Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory

Timeline

No history available yet.