CVE-2022-29970 is a path traversal vulnerability affecting Sinatra versions prior to 2.2.0, impacting Debian Linux and Sinatra applications. This flaw allows an unauthenticated attacker to access arbitrary files outside the intended public directory by crafting a malicious request. With a CVSS score of 7.5 (HIGH), it poses a significant risk of information disclosure (C:H) without requiring user interaction or complex attack methods. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or notable community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.0CPE matchmatch criteria | cpe:2.3:a:sinatrarb:sinatra:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.