Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Upgrade Sinatra and Rack to fix vulnerability
The security alert says: > [sinatra is] vulnerable to Reliance on Untrusted Inputs in a Security > Decision via the X-Forwarded-Host (XFH) header. When making a request to > a method with redirect applied, it is possible to trigger an Open > Redirect Attack by inserting an arbitrary address into this header. If > used for caching purposes, such as with servers like Nginx, or as a > reverse proxy, without handling the X-Forwarded-Host header, attackers > can potentially exploit Cache Poisoning or Routing-based SSRF. See https://github.com/gma/nesta/security/dependabot/30 for details.
- Loading branch information