The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Inefficient Regular Expression Complexity vulnerabilities in an interactive lesson.
Start learningThere is no fixed version for Minimos:latest
gitlab-logger-18.0
.
Note: Versions mentioned in the description apply only to the upstream gitlab-logger-18.0
package and not the gitlab-logger-18.0
package as distributed by Minimos
.
See How to fix?
for Minimos:latest
relevant fixed versions and status.
Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the If-Match
and If-None-Match
header parsing component of Sinatra, if the etag
method is used when constructing the response. Carefully crafted input can cause If-Match
and If-None-Match
header parsing in Sinatra to take an unexpected amount of time, possibly resulting in a denial of service attack vector. This header is typically involved in generating the ETag
header value. Any applications that use the etag
method when generating a response are impacted. Version 4.2.0 fixes the issue.