Download of code without integrity check in Sinatra - CVE-2022-45442

 

Download of code without integrity check in Sinatra - CVE-2022-45442

Published: January 24, 2023


Vulnerability identifier: #VU71475
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45442
CWE-ID: CWE-494
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system

The vulnerability exists due to software is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input. A remote attacker cam compromise the affected system.


Affected software

Sinatra
Ubuntu
openEuler
pcs (Red Hat package)
ruby-sinatra (Ubuntu package)
rubygem-sinatra
rubygem-sinatra-help

How to mitigate CVE-2022-45442

Install updates from vendor's website.

Sinatra - addressed in versions 2.2.3, 3.0.4
pcs (Red Hat package) - addressed in versions 0.10.2-4.el8_1.3, 0.10.4-6.el8_2.4, 0.10.8-1.el8_4.3, 0.10.12-6.el8_6.3, 0.10.14-5.el8_7.2, 0.11.1-10.el9_0.3, 0.11.3-4.el9_1.2
ruby-sinatra (Ubuntu package) - addressed in versions 1.4.7-3ubuntu0.1~esm2, 1.4.8-1ubuntu0.1~esm2, 2.0.8.1-1ubuntu0.1~esm2, 2.0.8.1-2+deb11u1build0.22.04.1
rubygem-sinatra - addressed in versions 2.0.3-3, 2.0.8.1-3, 2.0.8.1-4
rubygem-sinatra-help - addressed in versions 2.0.3-3, 2.0.8.1-3, 2.0.8.1-4

External References

Related Security Bulletins