USN-7031-1: Puma vulnerability
Published Sep 24, 2024
·Updated
It was discovered that Puma incorrectly handled parsing certain headers. A remote attacker could possibly use this issue to overwrite header values set by intermediate proxies by providing duplicate headers containing underscore characters.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/puma<6.4.2-4ubuntu4.3
6.4.2-4ubuntu4.3
Ubuntu Ubuntu=24.04
Event History
Sep 24, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7031-1?
USN-7031-1 is classified as a high severity vulnerability.
2
How do I fix USN-7031-1?
To fix USN-7031-1, update the Puma package to version 6.4.2-4ubuntu4.3 or later.
3
What systems are affected by USN-7031-1?
USN-7031-1 affects Ubuntu 24.04 systems using the Puma package.
4
Can USN-7031-1 lead to data leakage?
Yes, USN-7031-1 could potentially lead to data leakage due to header value overwriting.
5
Who discovered the issue in USN-7031-1?
The issue in USN-7031-1 was discovered by security researchers analyzing Puma's parsing of headers.