SUSE-SU-2022:1515-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1515-1
SUSE-SU-2022:1515-1
Summary: Security update for rubygem-puma
Details: This update for rubygem-puma fixes the following issues: rubygem-puma was updated to version 4.3.11: * CVE-2021-29509: Adjusted an incomplete fix for allows Denial of Service (DoS) (bsc#1188527) * CVE-2021-41136: Fixed request smuggling if HTTP header value contains the LF character (bsc#1191681) * CVE-2022-23634: Fixed information leak between requests (bsc#1196222)
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221515-1/, https://bugzilla.suse.com/1188527, https://bugzilla.suse.com/1191681, https://bugzilla.suse.com/1196222, https://www.suse.com/security/cve/CVE-2021-29509, https://www.suse.com/security/cve/CVE-2021-41136, https://www.suse.com/security/cve/CVE-2022-23634
Affected packages
Package
Name: rubygem-puma
Purl: pkg:rpm/suse/rubygem-puma&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015
Affected ranges
Type: ECOSYSTEM
Events:
