Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
HTTP Smuggling via Transfer-Encoding Header in Puma
Vulnerability Description
In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
HTTP请求的解释不一致性(HTTP请求私运)
Vulnerability Title
Puma 环境问题漏洞
Vulnerability Description
Puma是一款针对高并发应用的Web服务器。 Puma (RubyGem) 4.3.4之前版本和3.12.5之前版本中存在环境问题漏洞。攻击者可借助无效的transfer-encoding标头利用该漏洞实施HTTP走私攻击。
CVSS Information
N/A
Vulnerability Type
N/A