CVE-2018-11627 PUBLISHED

Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.

EPSS 0.40% · 60.4th percentile

Risk Scores

EPSS Score
0.40%
60.4th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSruby-sinatra0
Ubuntu:20.04:LTSruby-sinatra0, 2.0.5-4ubuntu1

Timeline

References

Open in Interactive Console →