Bugzilla – Bug 1095529
VUL-0: CVE-2018-11627: rubygem-sinatra: Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon aparams parser exception.
Last modified: 2024-06-07 07:52:39 UTC
CVE-2018-11627 Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-11627 http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-11627.html https://github.com/sinatra/sinatra/issues/1428 https://github.com/sinatra/sinatra/commit/12786867d6faaceaec62c7c2cb5b0e2dc074d71a
Seems like our SUSE codestreams are not affected: - SUSE:SLE-12-SP2:Update:Products:Cloud7:Update - SUSE:SLE-12-SP3:Update:Products:Cloud8:Update openSUSE:Factory on the other hand is affected.
Fixed for devel project: https://build.opensuse.org/request/show/613450
Leap 15.1 is affected reassigning back