Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22623
HistoryMar 03, 2020 - 5:17 a.m.

HTTP Response Splitting

2020-03-0305:17:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.01 Low

EPSS

Percentile

83.3%

puma is vulnerable to HTTP response splitting. The attack exist because it does not properly handle the CRLF (carriage feed or line return) characters injection in early hints response header, allowing an attacker to inject CRLF to end the the HTTP response header and manipulate with malicious content, such as additional headers or an entirely new response body. This vulnerability exists due to an incomplete fix of CVE-2020-5247.