CVE-2020-11076
HIGHPuma 3.0.0-3.12.5 and 4.0.0-4.3.3 - HTTP Request Smuggling via Invalid Transfer-Encoding Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-11076. PoCs published by dentarg.
AI-analyzed exploit summary This repository contains the source code and documentation for Puma, a Ruby web server, but does not include an exploit PoC for CVE-2020-11076. The README provides installation and configuration details for Puma.
Description
In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
Exploits (1)
This repository contains the source code and documentation for Puma, a Ruby web server, but does not include an exploit PoC for CVE-2020-11076. The README provides installation and configuration details for Puma.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N