In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
References
Configurations
History
No history.
Information
Published : 2020-05-22 15:15
Updated : 2024-11-21 04:56
NVD link : CVE-2020-11076
Mitre link : CVE-2020-11076
CVE.ORG link : CVE-2020-11076
JSON object : View
Products Affected
puma
- puma
debian
- debian_linux
fedoraproject
- fedora
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')