Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-16770

Опубликовано: 05 дек. 2019
Источник: nvd
CVSS3: 5.3
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough. This vulnerability is patched in Puma 4.3.1 and 3.12.2.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:puma:puma:*:*:*:*:*:ruby:*:*
Версия от 3.0.0 (включая) до 3.12.2 (исключая)
cpe:2.3:a:puma:puma:*:*:*:*:*:ruby:*:*
Версия от 4.0.0 (включая) до 4.3.1 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01587
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-770
CWE-770

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 6 лет назад

In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough. This vulnerability is patched in Puma 4.3.1 and 3.12.2.

CVSS3: 7.5
redhat
около 6 лет назад

In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough. This vulnerability is patched in Puma 4.3.1 and 3.12.2.

CVSS3: 5.3
debian
около 6 лет назад

In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client coul ...

CVSS3: 5.3
github
около 6 лет назад

A poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack

suse-cvrf
около 5 лет назад

Security update for rmt-server

EPSS

Процентиль: 81%
0.01587
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-770
CWE-770