HTTP Response Splitting in Puma
Published Feb 28, 2020
7.5
HIGHCVSS 3.1
EPSS 2.55%
Description
In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to end the header and inject malicious content, such as additional headers or an entirely new response body. This vulnerability is known as HTTP Response Splitting. While not an attack in itself, response splitting is a vector for several other attacks, such as cross-site scripting (XSS). This is related to CVE-2019-16254, which fixed this vulnerability for the WEBrick Ruby web server. This has been fixed in versions 4.3.2 and 3.12.3 by checking all headers for line endings and rejecting headers with those characters.
Affected products
-
Affected
- < 3.12.3
- ≥ 4.0.0, < 4.3.2
Configuration 1
Configuration 2
- 9.0
Configuration 3
- 30
- 31
- 32
No data.
CloudForms Management Engine 5
rubygem-puma
Will not fix
Red Hat 3scale API Management Platform 2
system
Affected
Red Hat Software Collections
rh-ror50-rubygem-puma
Will not fix
Red Hat Storage 3
rubygem-puma
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | rubygem-puma | Will not fix | n/a |
| Red Hat 3scale API Management Platform 2 | system | Affected | n/a |
| Red Hat Software Collections | rh-ror50-rubygem-puma | Will not fix | n/a |
| Red Hat Storage 3 | rubygem-puma | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the version of rubygem-puma shipped with Red Hat Gluster Storage 3, as it does not validate whether the header value could inject a CR or LF and inject their own HTTP response. Red Hat CloudForms uses affected RubyGem Puma, however, it is not vulnerable since it does not have custom code enabling early hints, HTTP/2 support or way to return 103 response. A future update may fix affected RubyGem.
References (18)
- https://access.redhat.com/security/cve/CVE-2020-5247 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1816187 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0295 Advisory
- https://github.com/advisories/GHSA-84j7-475p-hp8v Advisory
- https://github.com/puma/puma/commit/c36491756f68a9d6a8b3a49e7e5eb07fe6f1332f
- https://github.com/puma/puma/security/advisories/GHSA-84j7-475p-hp8v x_refsource_CONFIRMMitigationThird Party Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puma/CVE-2020-5247.yml
- https://lists.debian.org/debian-lts-announce/2022/05/msg00034.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BMJ3CGZ3DLBJ5WUUKMI5ZFXFJQMXJZIK/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DIHVO3CQMU7BZC7FCTSRJ33YDNS3GFPK/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJ3LL5F5QADB6LM46GXZETREAKZMQNRD/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BMJ3CGZ3DLBJ5WUUKMI5ZFXFJQMXJZIK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DIHVO3CQMU7BZC7FCTSRJ33YDNS3GFPK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NJ3LL5F5QADB6LM46GXZETREAKZMQNRD/
- https://nvd.nist.gov/vuln/detail/CVE-2020-5247
- https://owasp.org/www-community/attacks/HTTP_Response_Splitting x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-5247
- https://www.ruby-lang.org/en/news/2019/10/01/http-response-splitting-in-webrick-cve-2019-16254 x_refsource_MISCVendor Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub