Security update for rubygem-puma
This update for rubygem-puma fixes the following issues: Update to version 5.6.9. - CVE-2024-45614: improper header normalization allows for clients to clobber proxy set headers, which can lead to information leaks (bsc#1230848, fixed in an earlier update). - CVE-2024-21647: unbounded resource consumption due to invalid parsing of chunked encoding in HTTP/1.1 can lead to denial-of-service attacks (bsc#1218638, fixed in an earlier update) - CVE-2023-40175: incorrect behavior when parsing chunked transfer encoding bodies and zero-length Content-Length headers can lead to HTTP request smuggling attacks (bsc#1214425, fixed in an earlier update).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for rubygem-puma fixes the following issues: Update to version 5.6.9. - CVE-2024-45614: improper header normalization allows for clients to clobber proxy set headers, which can lead to information leaks (bsc#1230848, fixed in an earlier update). - CVE-2024-21647: unbounded resource consumption due to invalid parsing of chunked encoding in HTTP/1.1 can lead to denial-of-service attacks (bsc#1218638, fixed in an earlier update) - CVE-2023-40175: incorrect behavior when parsing chunked transfer encoding bodies and zero-length Content-Length headers can lead to HTTP request smuggling attacks (bsc#1214425, fixed in an earlier update).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1214425
- https://bugzilla.suse.com/1218638
- https://bugzilla.suse.com/1230848
- https://www.suse.com/security/cve/CVE-2023-40175
- https://www.suse.com/security/cve/CVE-2024-21647
- https://www.suse.com/security/cve/CVE-2024-45614
- https://www.suse.com/support/update/announcement/2025/suse-su-202503466-1/