SCA: security update for puma (GHSA-48w2-rm65-62xx)

low Tenable Cloud Security Plugin ID 410060

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Puma is a HTTP 1.1 server for Ruby/Rack applications. Prior to versions 5.5.1 and 4.3.9, using `puma` with
a proxy which forwards HTTP header values which contain the LF character could allow HTTP request
smugggling. A client could smuggle a request through a proxy, causing the proxy to send a response back to
another unknown client. The only proxy which has this behavior, as far as the Puma team is aware of, is
Apache Traffic Server. If the proxy uses persistent connections and the client adds another request in via
HTTP pipelining, the proxy may mistake it as the first request's body. Puma, however, would see it as two
requests, and when processing the second request, send back a response that the proxy does not expect. If
the proxy has reused the persistent connection to Puma to send another request for a different client, the
second response from the first client will be sent to the second client. This vulnerability was patched in
Puma 5.5.1 and 4.3.9. As a workaround, do not use Apache Traffic Server with `puma`. (CVE-2021-41136)

See Also

https://github.com/advisories/GHSA-48w2-rm65-62xx

Plugin Details

Severity: Low

ID: 410060

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.77

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Low

Base Score: 3.6

Temporal Score: 2.7

Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2021-41136

CVSS v3

Risk Factor: Low

Base Score: 3.7

Temporal Score: 3.2

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/12/2021

Vulnerability Publication Date: 10/12/2021

Reference Information

CVE: CVE-2021-41136

cwe: CWE-444