← Back

CVE-2020-5247

nvd nist
Published: Feb 28, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to end the header and inject malicious content, such as additional headers or an entirely new response body. This vulnerability is known as HTTP Response Splitting. While not an attack in itself, response splitting is a vector for several other attacks, such as cross-site scripting (XSS). This is related to CVE-2019-16254, which fixed this vulnerability for the WEBrick Ruby web server. This has been fixed in versions 4.3.2 and 3.12.3 by checking all headers for line endings and rejecting headers with those characters.

Affected (11)

Products: Puma: Puma · Ruby Lang: Ruby · Debian: Debian Linux · +1 more
Show all products
1 product
Puma
1 product
Ruby
1 product
Debian Linux
1 product
Fedora
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Puma
Up to 3.12.3
From 4.0.0 to 4.3.2
Ruby Lang
Up to 2.3.0
From 2.4.0 to 2.4.7
From 2.5.0 to 2.5.6
From 2.6.0 to 2.6.4
Version 2.7.0 preview1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31
Version 32

References (14)

Source: security-advisories@github.com
MitigationThird Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.