An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows. Path traversal is possible via backslash characters.
| Software | From | Fixed in |
|---|---|---|
| sinatrarb / sinatra | 2.0.0 | 2.0.0.x |
| sinatrarb / sinatra | 2.0.0-rc1 | 2.0.0-rc1.x |
| sinatrarb / sinatra | 2.0.0-rc2 | 2.0.0-rc2.x |
| sinatrarb / sinatra | 2.0.0-rc3 | 2.0.0-rc3.x |
| sinatrarb / sinatra | 2.0.0-rc4 | 2.0.0-rc4.x |
| sinatrarb / sinatra | 2.0.0-rc5 | 2.0.0-rc5.x |
| sinatrarb / sinatra | 2.0.0-rc6 | 2.0.0-rc6.x |
| sinatrarb / sinatra | 2.0.0-beta2 | 2.0.0-beta2.x |
| sinatrarb / sinatra | 2.0.1-rc1 | 2.0.1-rc1.x |
sinatra
|
2.0.0.beta1 | 2.0.1 |