Back

HIGH

HTTP Response Splitting in Puma

Published Feb 28, 2020

Description

In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to end the header and inject malicious content, such as additional headers or an entirely new response body. This vulnerability is known as HTTP Response Splitting. While not an attack in itself, response splitting is a vector for several other attacks, such as cross-site scripting (XSS). This is related to CVE-2019-16254, which fixed this vulnerability for the WEBrick Ruby web server. This has been fixed in versions 4.3.2 and 3.12.3 by checking all headers for line endings and rejecting headers with those characters.

Affected products

Remediation

Red Hat statement

This issue affects the version of rubygem-puma shipped with Red Hat Gluster Storage 3, as it does not validate whether the header value could inject a CR or LF and inject their own HTTP response. Red Hat CloudForms uses affected RubyGem Puma, however, it is not vulnerable since it does not have custom code enabling early hints, HTTP/2 support or way to return 103 response. A future update may fix affected RubyGem.

Weaknesses (2)

References (18)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Feb 28, 2020
Updated Aug 4, 2024
Reserved Jan 2, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Mar 2, 2020
Bugzilla 1816187

ENISA EUVD

Assigner GitHub_M
Published Feb 28, 2020
Updated Aug 4, 2024