Lucene search

K
redhatcveRedhat.comRH:CVE-2020-5247
HistoryMar 23, 2020 - 2:08 p.m.

CVE-2020-5247

2020-03-2314:08:38
redhat.com
access.redhat.com
8

0.01 Low

EPSS

Percentile

83.3%

A flaw was discovered in rubygem-puma, where it did not properly forbid untrusted input in a response header. This flaw allows an attacker with the ability to tamper with HTTP headers to insert a new-line and insert malicious content, allowing an HTTP response splitting, which exposes the risk of attacks such as cross-site scripting.