Security update for rubygem-puma
This update for rubygem-puma fixes the following issues: rubygem-puma was updated to version 4.3.11: * CVE-2021-29509: Adjusted an incomplete fix for allows Denial of Service (DoS) (bsc#1188527) * CVE-2021-41136: Fixed request smuggling if HTTP header value contains the LF character (bsc#1191681) * CVE-2022-23634: Fixed information leak between requests (bsc#1196222)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for rubygem-puma fixes the following issues: rubygem-puma was updated to version 4.3.11: * CVE-2021-29509: Adjusted an incomplete fix for allows Denial of Service (DoS) (bsc#1188527) * CVE-2021-41136: Fixed request smuggling if HTTP header value contains the LF character (bsc#1191681) * CVE-2022-23634: Fixed information leak between requests (bsc#1196222)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1188527
- https://bugzilla.suse.com/1191681
- https://bugzilla.suse.com/1196222
- https://www.suse.com/security/cve/CVE-2021-29509
- https://www.suse.com/security/cve/CVE-2021-41136
- https://www.suse.com/security/cve/CVE-2022-23634
- https://www.suse.com/support/update/announcement/2022/suse-su-20221515-1/