VDB

GCVE-110-MAGEIA-2022-280

GCVE-110-MAGEIA-2022-280
Advisory Published
Vulnetix · Advisory published August 13, 2022
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. (CVE-2022-29970)

Affected Products

VendorProductVersionsPlatforms
Mageiaruby-sinatra0 (affected), 2.0.8.1-1.1.mga8 (unaffected)

Browse GCVE Records

74,557 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›