Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian 11: DSA-5146-1 Critical: Puma Information Disclosure Issue

debian
Calendar Grey May 24, 2022
Debian Logo
Apache HTTP Server patches on Ubuntu address vulnerabilities related to request forgery and information leakage.
Multiple security vulnerabilities were discovered in Puma, a HTTP server for Ruby/Rack applications, which could result in HTTP request smuggling or information disclosure

Summary

Multiple security vulnerabilities were discovered in Puma, a HTTP server
for Ruby/Rack applications, which could result in HTTP request smuggling
or information disclosure.

For the stable distribution (bullseye), this problem has been fixed in
version 4.3.8-1+deb11u2.

We recommend that you upgrade your puma packages.

For the detailed security status of puma please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/puma

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: puma
CVE ID: CVE-2021-41136 CVE-2022-23634 CVE-2022-24790

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here