HTTP Smuggling via Transfer-Encoding Header in Puma
Published May 22, 2020
7.5
HIGHCVSS 3.1
EPSS 4.09%
Description
In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
Affected products
-
Affected
- < 3.12.5
- ≥ 4.0.0, < 4.3.4
Configuration 1
Configuration 2
- 33
Configuration 3
- 9.0
No data.
CloudForms Management Engine 5
rubygem-puma
Will not fix
Red Hat Storage 3
rubygem-puma
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | rubygem-puma | Will not fix | n/a |
| Red Hat Storage 3 | rubygem-puma | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Gluster Storage 3 Web Administration component uses affected RubyGem Puma, which does not have the http body chunk verification.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (15)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00034.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00038.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-11076 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1842539 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0447 Advisory
- https://github.com/advisories/GHSA-x7jg-6pwg-fx5h Advisory
- https://github.com/puma/puma/blob/master/History.md#434435-and-31253126--2020-05-22 x_refsource_MISCRelease Notes
- https://github.com/puma/puma/commit/f24d5521295a2152c286abb0a45a1e1e2bd275bd x_refsource_MISCPatch
- https://github.com/puma/puma/security/advisories/GHSA-x7jg-6pwg-fx5h x_refsource_CONFIRMThird Party Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puma/CVE-2020-11076.yml
- https://lists.debian.org/debian-lts-announce/2020/10/msg00009.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SKIY5H67GJIGJL6SMFWFLUQQQR3EMVPR/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SKIY5H67GJIGJL6SMFWFLUQQQR3EMVPR/
- https://nvd.nist.gov/vuln/detail/CVE-2020-11076
- https://www.cve.org/CVERecord?id=CVE-2020-11076
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub