First published: Tue Sep 24 2024(Updated: )
USN-7031-1 fixed CVE-2024-45614 in Puma for Ubuntu 24.04 LTS. This update fixes the CVE for Ubuntu 22.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that Puma incorrectly handled parsing certain headers. A remote attacker could possibly use this issue to overwrite header values set by intermediate proxies by providing duplicate headers containing underscore characters.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/puma | <5.5.2-2ubuntu2+esm2 | 5.5.2-2ubuntu2+esm2 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/puma | <3.12.4-1ubuntu2+esm2 | 3.12.4-1ubuntu2+esm2 |
Ubuntu Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.