5
CVSSv2

CVE-2020-11076

Published: 22/05/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 447
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

In Puma (RubyGem) prior to 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

puma puma

fedoraproject fedora 33

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #972102 CVE-2020-11076 CVE-2020-11077 Package: puma; Maintainer for puma is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Source for puma is src:puma (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 12 Oct 2020 18:15:01 ...