Path traversal in Sinatra - CVE-2022-29970

 

Path traversal in Sinatra - CVE-2022-29970

Published: May 19, 2022


Vulnerability identifier: #VU63415
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29970
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

Sinatra
IBM Watson Machine Learning Accelerator
Red Hat Satellite
SUSE OpenStack Cloud Crowbar
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
pcs (Red Hat package)
ruby2.1-rubygem-sinatra
ruby-sinatra (Ubuntu package)

How to mitigate CVE-2022-29970

Install update from vendor's website.

Sinatra - update to 2.2.0
pcs (Red Hat package) - addressed in versions 0.10.2-4.el8_1.2, 0.10.4-6.el8_2.2, 0.10.8-1.el8_4.1, 0.10.12-6.el8_6.1, 0.11.1-10.el9_0.1
ruby2.1-rubygem-sinatra - update to 1.4.6-3.3.1
ruby-sinatra (Ubuntu package) - addressed in versions 1.4.7-3ubuntu0.1~esm2, 1.4.8-1ubuntu0.1~esm2, 2.0.8.1-1ubuntu0.1~esm2, 2.0.8.1-2+deb11u1build0.22.04.1

External References

Related Security Bulletins