Lucene search

K
redhatcveRedhat.comRH:CVE-2020-5249
HistoryMar 23, 2020 - 2:08 p.m.

CVE-2020-5249

2020-03-2314:08:48
redhat.com
access.redhat.com
11

0.002 Low

EPSS

Percentile

59.8%

A flaw was discovered in rubygem-puma, where it did not properly forbid untrusted input in an early-hints header. This flaw allows an attacker with the ability to tamper with HTTP headers to insert a carriage return character to end the header and then insert malicious content, allowing an HTTP response splitting, which exposes the risk of attacks such as cross-site scripting.