Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-23634

Опубликовано: 11 фев. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 8

Описание

Puma is a Ruby/Rack web server built for parallelism. Prior to puma version 5.6.2, puma may not always call close on the response body. Rails, prior to version 7.0.2.2, depended on the response body being closed in order for its CurrentAttributes implementation to work correctly. The combination of these two behaviors (Puma not closing the body + Rails' Executor implementation) causes information leakage. This problem is fixed in Puma versions 5.6.2 and 4.3.11. This problem is fixed in Rails versions 7.02.2, 6.1.4.6, 6.0.4.6, and 5.2.6.2. Upgrading to a patched Rails or Puma version fixes the vulnerability.

РелизСтатусПримечание
devel

not-affected

5.6.5-3ubuntu1
esm-apps/focal

released

3.12.4-1ubuntu2+esm1
esm-apps/jammy

released

5.5.2-2ubuntu2+esm1
focal

ignored

end of standard support, was needed
impish

ignored

end of life
jammy

needed

kinetic

ignored

end of life, was needed
lunar

not-affected

5.6.5-3ubuntu1
mantic

not-affected

5.6.5-3ubuntu1
noble

not-affected

5.6.5-3ubuntu1

Показывать по

EPSS

Процентиль: 53%
0.00303
Низкий

4.3 Medium

CVSS2

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
redhat
больше 3 лет назад

Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being closed in order for its `CurrentAttributes` implementation to work correctly. The combination of these two behaviors (Puma not closing the body + Rails' Executor implementation) causes information leakage. This problem is fixed in Puma versions 5.6.2 and 4.3.11. This problem is fixed in Rails versions 7.02.2, 6.1.4.6, 6.0.4.6, and 5.2.6.2. Upgrading to a patched Rails _or_ Puma version fixes the vulnerability.

CVSS3: 8
nvd
больше 3 лет назад

Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being closed in order for its `CurrentAttributes` implementation to work correctly. The combination of these two behaviors (Puma not closing the body + Rails' Executor implementation) causes information leakage. This problem is fixed in Puma versions 5.6.2 and 4.3.11. This problem is fixed in Rails versions 7.02.2, 6.1.4.6, 6.0.4.6, and 5.2.6.2. Upgrading to a patched Rails _or_ Puma version fixes the vulnerability.

CVSS3: 8
debian
больше 3 лет назад

Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` ...

CVSS3: 8
github
больше 3 лет назад

Puma used with Rails may lead to Information Exposure

CVSS3: 8
fstec
больше 3 лет назад

Уязвимость HTTP-сервера для Ruby/Rack приложений Puma, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 53%
0.00303
Низкий

4.3 Medium

CVSS2

8 High

CVSS3