CVE-2022-23634
Description
Puma is a Ruby/Rack web server built for parallelism. Prior to puma version 5.6.2, puma may not always call close on the response body. Rails, prior to version 7.0.2.2, depended on the response body being closed in order for its CurrentAttributes implementation to work correctly. The combination of these two behaviors (Puma not closing the body + Rails' Executor implementation) causes information leakage. This problem is fixed in Puma versions 5.6.2 and 4.3.11. This problem is fixed in Rails versions 7.02.2, 6.1.4.6, 6.0.4.6, and 5.2.6.2. Upgrading to a patched Rails _or_ Puma version fixes the vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pumaRubyGems | >= 5.0.0, < 5.6.2 | 5.6.2 |
pumaRubyGems | < 4.3.11 | 4.3.11 |
Affected products
18cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- ghsa-coords9 versionspkg:gem/pumapkg:rpm/opensuse/ruby3.2-rubygem-puma&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-puma&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/rubygem-puma&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/rubygem-puma&distro=openSUSE%20Tumbleweedpkg:rpm/suse/rubygem-puma&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015pkg:rpm/suse/rubygem-puma&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP1pkg:rpm/suse/rubygem-puma&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP2pkg:rpm/suse/rubygem-puma&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP3
>= 5.0.0, < 5.6.2+ 8 more
- (no CPE)range: >= 5.0.0, < 5.6.2
- (no CPE)range: < 6.0.0-2.1
- (no CPE)range: < 4.3.11-150000.3.6.2
- (no CPE)range: < 4.3.11-150000.3.6.2
- (no CPE)range: < 5.6.2-1.1
- (no CPE)range: < 4.3.11-150000.3.6.2
- (no CPE)range: < 4.3.11-150000.3.6.2
- (no CPE)range: < 4.3.11-150000.3.6.2
- (no CPE)range: < 4.3.11-150000.3.6.2
- puma/pumav5Range: >= 5.0.0, < 5.6.2
Patches
Vulnerability mechanics
References
17- github.com/puma/puma/commit/b70f451fe8abc0cff192c065d549778452e155bbnvdPatchThird Party AdvisoryWEB
- github.com/puma/puma/security/advisories/GHSA-rmj8-8hhh-gv5hnvdPatchThird Party AdvisoryWEB
- groups.google.com/g/ruby-security-ann/c/FkTM-_7zSNA/m/K2RiMJBlBAAJnvdMailing ListMitigationPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-rmj8-8hhh-gv5hnvdThird Party AdvisoryADVISORY
- github.com/advisories/GHSA-wh98-p28r-vrc9nvdMitigationNot ApplicableThird Party AdvisoryADVISORY
- lists.debian.org/debian-lts-announce/2022/05/msg00034.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2022/08/msg00015.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-23634ghsaADVISORY
- security.gentoo.org/glsa/202208-28nvdThird Party AdvisoryWEB
- www.debian.org/security/2022/dsa-5146nvdThird Party AdvisoryWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/puma/CVE-2022-23634.ymlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/F6YWGIIKL7KKTS3ZOAYMYPC7D6WQ5OA5ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/L7NESIBFCNSR3XH7LXDPKVMSUBNUB43GghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/TUBFJ44NCKJ34LECZRAP4N5VL6USJSIBghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F6YWGIIKL7KKTS3ZOAYMYPC7D6WQ5OA5/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7NESIBFCNSR3XH7LXDPKVMSUBNUB43G/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TUBFJ44NCKJ34LECZRAP4N5VL6USJSIB/nvd
News mentions
0No linked articles in our index yet.