← Back

CVE-2022-23634

nvd nist
Published: Feb 11, 2022Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being closed in order for its `CurrentAttributes` implementation to work correctly. The combination of these two behaviors (Puma not closing the body + Rails' Executor implementation) causes information leakage. This problem is fixed in Puma versions 5.6.2 and 4.3.11. This problem is fixed in Rails versions 7.02.2, 6.1.4.6, 6.0.4.6, and 5.2.6.2. Upgrading to a patched Rails _or_ Puma version fixes the vulnerability.

Affected (12)

Products: Puma: Puma · Rubyonrails: Rails · Debian: Debian Linux · +1 more
Show all products
1 product
Puma
1 product
Rails
1 product
Debian Linux
1 product
Fedora
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Puma
Before 4.3.11
From 5.0.0 to 5.6.2
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Rubyonrails
From 5.0.0 to 5.2.6.2
From 6.0.0 to 6.0.4.6
From 6.1.0 to 6.1.4.6
From 7.0.0 to 7.0.2.2
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Version 9.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 35
Version 36
Version 37

References (24)

Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
MitigationNot ApplicableThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Mailing ListMitigationPatchThird Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationNot ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.