diff --git a/gems/sinatra/CVE-2018-7212.yml b/gems/rack-protection/CVE-2018-7212.yml similarity index 62% rename from gems/sinatra/CVE-2018-7212.yml rename to gems/rack-protection/CVE-2018-7212.yml index 4bfaca8630..afc51242d8 100644 --- a/gems/sinatra/CVE-2018-7212.yml +++ b/gems/rack-protection/CVE-2018-7212.yml @@ -1,11 +1,12 @@ --- -gem: sinatra +gem: rack-protection cve: 2018-7212 url: https://github.com/sinatra/sinatra/pull/1379 title: Path traversal is possible via backslash characters on Windows. date: 2018-02-18 description: | - An issue was discovered in Sinatra 2.x before 2.0.1 on Windows. Path traversal + An issue was discovered in rack-protection 2.x before 2.0.1 on Windows. Path traversal is possible via backslash characters. patched_versions: - - ">= 2.0.1" \ No newline at end of file + - ">= 2.0.1" + - "~> 1.5.4"