CVE-2020-11076: HTTP Smuggling via Transfer-Encoding Header in Puma
Impact
By using an invalid transfer-encoding header, an attacker could smuggle an HTTP response.
Originally reported by @ZeddYu, who has our thanks for the detailed report.
Patches
The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
For more information
If you have any questions or comments about this advisory:
Open an issue in Puma See our security policy
Other sources
In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
— Ubuntu
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-11076.
What is the severity of CVE-2020-11076?
The severity of CVE-2020-11076 is high, with a severity value of 7.5.
How can an attacker exploit CVE-2020-11076?
An attacker can exploit CVE-2020-11076 by using an invalid transfer-encoding header to smuggle an HTTP response.
Which versions of Puma are affected by CVE-2020-11076?
Puma versions 3.0.0 to 3.12.5 and 4.0.0 to 4.3.4 are affected by CVE-2020-11076.
How can I fix CVE-2020-11076?
You can fix CVE-2020-11076 by updating Puma to version 3.12.5 or 4.3.4, depending on the version you are currently using.