Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 10: DLA-3083-1 Critical: Puma DoS and Request Smuggling Threats

debian lts
Calendar Grey August 27, 2022
Dist Debian Esm H88
Several vulnerabilities identified in Puma impacting web server functionality, notably including denial of service conditions and request smuggling exploits.
Multiple security issues have been found in puma, a web server for ruby/rack applications

Summary

CVE-2021-29509

Keepalive Connections Causing Denial Of Service in puma.

CVE-2021-41136

puma with a proxy which forwards HTTP header values which contain
the LF character could allow HTTP request smugggling. A client
could smuggle a request through a proxy, causing the proxy to send
a response back to another unknown client.

CVE-2022-23634

puma may not always call `close` on the response body. Rails,
prior to version `7.0.2.2`, depended on the response body being
closed in order for its `CurrentAttributes` implementation to work
correctly. The combination of these two behaviors (Puma not
closing the body + Rails' Executor implementation) causes
information leakage.

CVE-2022-24790

using Puma behind a proxy that does not properly validate that the
incoming HTTP request matches the RFC7230 standard, Puma and the
frontend proxy may disagree on where a request starts and ends.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: puma
Version: 3.12.0-2+deb10u3
CVE ID: CVE-2021-29509 CVE-2021-41136 CVE-2022-23634

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here