Skip to content

Commit de10847

Browse files
ThomasKoppensteinerRubySec CI
authored and
RubySec CI
committedNov 19, 2024·
Updated advisory posts against rubysec/ruby-advisory-db@abe5f92
1 parent 96ee92a commit de10847

File tree

1 file changed

+7
-3
lines changed

1 file changed

+7
-3
lines changed
 

‎advisories/_posts/2024-11-01-CVE-2024-21510.md

+7-3
Original file line numberDiff line numberDiff line change
@@ -24,13 +24,17 @@ advisory:
2424
handling the X-Forwarded-Host header, attackers can potentially
2525
exploit Cache Poisoning or Routing-based SSRF.
2626
cvss_v3: 5.4
27-
notes: Never patched
27+
patched_versions:
28+
- ">= 4.1.0"
2829
related:
2930
url:
3031
- https://nvd.nist.gov/vuln/detail/CVE-2024-21510
3132
- https://security.snyk.io/vuln/SNYK-RUBY-SINATRA-6483832
32-
- https://github.com/sinatra/sinatra/pull/2010
33+
- https://github.com/advisories/GHSA-hxx2-7vcw-mqr3
3334
- https://github.com/sinatra/sinatra/blob/b626e2d82c23b4fde0b51782fd32ca27ccde1d1a/lib/sinatra/base.rb#L319
3435
- https://github.com/sinatra/sinatra/blob/b626e2d82c23b4fde0b51782fd32ca27ccde1d1a/lib/sinatra/base.rb#L323C1-L343C17
35-
- https://github.com/advisories/GHSA-hxx2-7vcw-mqr3
36+
- https://github.com/sinatra/sinatra/issues/2052
37+
- https://github.com/sinatra/sinatra/pull/2010
38+
- https://github.com/sinatra/sinatra/pull/2053
39+
- https://github.com/sinatra/sinatra/commit/cd3e00de20ddaff34ea30f7a74a7b9dad189d1d8
3640
---

0 commit comments

Comments
 (0)
Please sign in to comment.