Beveiligingsadvies

CVE-2020-11076

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-05-22 14:50:12
Laatst bijgewerkt 2024-08-04 11:21:14
Toegewezen door GitHub_M
CVSS-score 7.5
Status PUBLISHED

Beschrijving

In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.