Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-10705
HistoryFeb 15, 2022 - 12:00 a.m.

Puma Information Breach Vulnerability

2022-02-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
11

0.002 Low

EPSS

Percentile

56.7%

Puma is a web server for highly concurrent applications from Evan Phoenix, a personal developer in the U.S. Puma is vulnerable to an information disclosure vulnerability that stems from the fact that prior to puma version 5.6.2, puma may not always call close on the response body, and prior to version 7.0.2.2, Rails relied on closing the response body so that its “CurrentAttributes” implementation works correctly. The combination of these two behaviors (Puma does not close the body Rails’ Executor implementation) can lead to information leakage. No details of the vulnerability are currently available.

CPENameOperatorVersion
puma pumalt5.6.2