CVE-2022-23634 Information

Description

Puma is a Ruby/Rack web server built for parallelism. Prior to puma version 5.6.2 puma may not always call close on the response body. Rails prior to version 7.0.2.2 depended on the response body being closed in order for its CurrentAttributes implementation to work correctly. The combination of these two behaviors (Puma not closing the body + Rails’ Executor implementation) causes information leakage. This problem is fixed in Puma versions 5.6.2 and 4.3.11. This problem is fixed in Rails versions 7.02.2 6.1.4.6 6.0.4.6 and 5.2.6.2. Upgrading to a patched Rails or Puma version fixes the vulnerability.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

https://github.com/puma/puma/security/advisories/GHSA-rmj8-8hhh-gv5h https://github.com/puma/puma/commit/b70f451fe8abc0cff192c065d549778452e155bb https://groups.google.com/g/ruby-security-ann/c/FkTM-_7zSNA/m/K2RiMJBlBAAJ?utm_medium=email&utm_source=footer&pli=1 https://github.com/advisories/GHSA-rmj8-8hhh-gv5h https://github.com/advisories/GHSA-wh98-p28r-vrc9 https://www.debian.org/security/2022/dsa-5146 https://lists.debian.org/debian-lts-announce/2022/05/msg00034.html

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

5.9

Share on: