In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-05-22 15:15
Updated : 2020-10-07 13:15
NVD link : CVE-2020-11076
Mitre link : CVE-2020-11076
JSON object : View
Products Affected
puma
- puma
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
