Lucene search

K
osvGoogleOSV:CVE-2022-29970
HistoryMay 02, 2022 - 5:15 a.m.

CVE-2022-29970

2022-05-0205:15:06
Google
osv.dev
9
sinatra
static files
path validation
security
cve-2022-29970

EPSS

0.002

Percentile

61.2%

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.