HTTP Response Splitting (Early Hints) in Puma
Published Mar 2, 2020
6.5
MEDIUMCVSS 3.1
EPSS 1.57%
Description
In Puma (RubyGem) before 4.3.3 and 3.12.4, if an application using Puma allows untrusted input in an early-hints header, an attacker can use a carriage return character to end the header and inject malicious content, such as additional headers or an entirely new response body. This vulnerability is known as HTTP Response Splitting. While not an attack in itself, response splitting is a vector for several other attacks, such as cross-site scripting (XSS). This is related to CVE-2020-5247, which fixed this vulnerability but only for regular responses. This has been fixed in 4.3.3 and 3.12.4.
Affected products
-
- Version < 3.12.4StatusaffectedConstraints-
- Version >= 4.0.0, < 4.3.3StatusaffectedConstraints-
- Version
No data.
CloudForms Management Engine 5
rubygem-puma
Will not fix
Red Hat Software Collections
rh-ror50-rubygem-puma
Will not fix
Red Hat Storage 3
rubygem-puma
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | rubygem-puma | Will not fix | n/a |
| Red Hat Software Collections | rh-ror50-rubygem-puma | Will not fix | n/a |
| Red Hat Storage 3 | rubygem-puma | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the version of rubygem-puma shipped with Red Hat Gluster Storage 3, as it does not prevent HTTP Response splitting via CR in early hints. Red Hat CloudForms uses affected RubyGem Puma, however, it is not vulnerable since it does not have custom code enabling early hints, HTTP/2 support or way to return 103 response. A future update may fix affected RubyGem.
References (16)
- https://access.redhat.com/security/cve/CVE-2020-5249 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1816181 Issue Tracking
- https://github.com/advisories/GHSA-33vf-4xgg-9r58 Advisory
- https://github.com/puma/puma/commit/c22712fc93284a45a93f9ad7023888f3a65524f3 x_refsource_MISCPatchThird Party Advisory
- https://github.com/puma/puma/security/advisories/GHSA-33vf-4xgg-9r58 x_refsource_CONFIRMThird Party Advisory
- https://github.com/puma/puma/security/advisories/GHSA-84j7-475p-hp8v x_refsource_MISCThird Party Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puma/CVE-2020-5249.yml
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BMJ3CGZ3DLBJ5WUUKMI5ZFXFJQMXJZIK/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DIHVO3CQMU7BZC7FCTSRJ33YDNS3GFPK/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJ3LL5F5QADB6LM46GXZETREAKZMQNRD/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BMJ3CGZ3DLBJ5WUUKMI5ZFXFJQMXJZIK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DIHVO3CQMU7BZC7FCTSRJ33YDNS3GFPK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NJ3LL5F5QADB6LM46GXZETREAKZMQNRD/
- https://nvd.nist.gov/vuln/detail/CVE-2020-5249
- https://owasp.org/www-community/attacks/HTTP_Response_Splitting x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-5249
Change history (0)
No recorded changes yet.