Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
| Software | From | Fixed in |
|---|---|---|
| sinatrarb / sinatra | - | 2.0.2 |
| redhat / cloudforms | 4.6 | 4.6.x |
| redhat / cloudforms | 4.7 | 4.7.x |
sinatra
|
2.0.0 | 2.0.2 |