CVE-2024-21647
puma - security update
5.9
MEDIUM
CVSS 3.1
EPSS 2.5%
Description
Puma is a web server for Ruby/Rack applications built for parallelism. Prior to version 6.4.2, puma exhibited incorrect behavior when parsing chunked transfer encoding bodies in a way that allowed HTTP request smuggling. Fixed versions limits the size of chunk extensions. Without this limit, an attacker could cause unbounded resource (CPU, network bandwidth) consumption. This vulnerability has been fixed in versions 6.4.2 and 5.6.8.
How to fix CVE-2024-21647
To remediate CVE-2024-21647, upgrade the affected package to a fixed version below.
- —upgrade to 4.3.8-1+deb11u3 or later
- —upgrade to 4.3.8-1+deb11u3 or later
- —upgrade to 6.4.2 or later
Is CVE-2024-21647 being exploited?
Low — EPSS is 2.5%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 4.3.8-1+deb11u3
- from 0, < 4.3.8-1+deb11u3
- >= 6.0.0, < 6.4.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |