Potential DOS attack in Puma
Published Dec 5, 2019
7.5
HIGHCVSS 3.1
EPSS 2.01%
Description
In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough. This vulnerability is patched in Puma 4.3.1 and 3.12.2.
Affected products
-
Affected
- ≥ < 4.3.1, < 4.3.1
No data.
CloudForms Management Engine 5
rubygem-puma
Will not fix
Red Hat 3scale API Management Platform 2
rubygem-puma
Not affected
Red Hat Software Collections
rh-ror50-rubygem-puma
Will not fix
Red Hat Storage 3
rubygem-puma
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | rubygem-puma | Will not fix | n/a |
| Red Hat 3scale API Management Platform 2 | rubygem-puma | Not affected | n/a |
| Red Hat Software Collections | rh-ror50-rubygem-puma | Will not fix | n/a |
| Red Hat Storage 3 | rubygem-puma | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Reverse proxies in front of Puma could be configured to always allow less than X keepalive connections to a Puma cluster or process, where X is the number of threads configured in Puma's thread pool.
Red Hat statement
Red Hat CloudForms uses affected RubyGem Puma, however, not vulnerable since after increasing multiple keepalive connections compare to threads available; additional connections have not waited long. Red Hat Gluster Storage Web Administration component uses affected RubyGem Puma.
Red Hat mitigation
Reverse proxies in front of Puma could be configured to always allow less than X keepalive connections to a Puma cluster or process, where X is the number of threads configured in Puma's thread pool.
References (9)
- https://access.redhat.com/security/cve/CVE-2019-16770 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1831297 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0786 Advisory
- https://github.com/advisories/GHSA-7xx3-m584-x994 Advisory
- https://github.com/puma/puma/security/advisories/GHSA-7xx3-m584-x994 x_refsource_CONFIRMMitigationThird Party Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puma/CVE-2019-16770.yml
- https://lists.debian.org/debian-lts-announce/2022/05/msg00034.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-16770
- https://www.cve.org/CVERecord?id=CVE-2019-16770
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-16770 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1831297 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0786 | Advisory | |
| https://github.com/advisories/GHSA-7xx3-m584-x994 | Advisory | |
| https://github.com/puma/puma/security/advisories/GHSA-7xx3-m584-x994 | x_refsource_CONFIRMMitigationThird Party Advisory | |
| https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puma/CVE-2019-16770.yml | ||
| https://lists.debian.org/debian-lts-announce/2022/05/msg00034.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-16770 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-16770 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub