← Back

CVE-2020-11077

nvd nist
Published: May 22, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Puma (RubyGem) before 4.3.5 and 3.12.6, a client could smuggle a request through a proxy, causing the proxy to send a response back to another unknown client. If the proxy uses persistent connections and the client adds another request in via HTTP pipelining, the proxy may mistake it as the first request's body. Puma, however, would see it as two requests, and when processing the second request, send back a response that the proxy does not expect. If the proxy has reused the persistent connection to Puma to send another request for a different client, the second response from the first client will be sent to the second client. This is a similar but different vulnerability from CVE-2020-11076. The problem has been fixed in Puma 3.12.6 and Puma 4.3.5.

Affected (6)

Products: Puma: Puma · Fedoraproject: Fedora · Debian: Debian Linux · +1 more
Show all products
1 product
Puma
1 product
Fedora
1 product
Debian Linux
1 product
Leap
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Puma
From 3.0.0 to 3.12.6
From 4.0.0 to 4.3.5
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 33
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.1
Version 15.2

References (12)

Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.