Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities: Bump puma gem from v6.4.2 to v6.4.3 #1560

Merged
merged 1 commit into from
Sep 24, 2024

Conversation

Ivanov-Anton
Copy link
Collaborator

@Ivanov-Anton Ivanov-Anton commented Sep 24, 2024

Description

Name: puma
Version: 6.4.2
CVE: https://github.com/advisories/GHSA-9hf4-67fc-4vf4
GHSA: https://github.com/advisories/GHSA-9hf4-67fc-4vf4
Criticality: Medium
URL: [GHSA-9hf4-67fc-4vf4](https://github.com/puma/puma/security/advisories/GHSA-9hf4-67fc-4vf4)
Title: Puma's header normalization allows for client to clobber proxy set headers
Solution: upgrade to '~> 5.6.9', '>= 6.4.3'

Name: puma
Version: 6.4.2
CVE: CVE-2024-45614
GHSA: GHSA-9hf4-67fc-4vf4
Criticality: Medium
URL: GHSA-9hf4-67fc-4vf4
Title: Puma's header normalization allows for client to clobber proxy set headers
Solution: upgrade to '~> 5.6.9', '>= 6.4.3'
@Ivanov-Anton Ivanov-Anton changed the title bump puma gem Vulnerabilities: Bump puma gem from v6.4.2 to v6.4.3 Sep 24, 2024
@Ivanov-Anton Ivanov-Anton self-assigned this Sep 24, 2024
@Ivanov-Anton Ivanov-Anton added the Waiting for code review It means that the owner or member of the repositor can do a code review. label Sep 24, 2024
@dmitry-sinina dmitry-sinina merged commit ef1eae7 into master Sep 24, 2024
11 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Waiting for code review It means that the owner or member of the repositor can do a code review.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants