{"schema_version":"1.7.3","id":"UBUNTU-CVE-2022-23634","published":"2022-02-11T22:15:00Z","modified":"2026-02-04T02:56:09.278657Z","related":["USN-6682-1"],"upstream":["CVE-2022-23634"],"details":"Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being closed in order for its `CurrentAttributes` implementation to work correctly. The combination of these two behaviors (Puma not closing the body + Rails' Executor implementation) causes information leakage. This problem is fixed in Puma versions 5.6.2 and 4.3.11. This problem is fixed in Rails versions 7.02.2, 6.1.4.6, 6.0.4.6, and 5.2.6.2. Upgrading to a patched Rails _or_ Puma version fixes the vulnerability.","affected":[{"package":{"name":"puma","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/puma@3.12.4-1ubuntu2+esm1?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.12.4-1ubuntu2+esm1"}]}],"versions":["3.12.0-2ubuntu1","3.12.0-4ubuntu1","3.12.4-1ubuntu2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"puma","binary_version":"3.12.4-1ubuntu2+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-23634.json"}},{"package":{"name":"puma","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/puma@5.5.2-2ubuntu2+esm1?arch=source&distro=esm-apps/jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.5.2-2ubuntu2+esm1"}]}],"versions":["4.3.6-1ubuntu4","5.5.2-2ubuntu2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"puma","binary_version":"5.5.2-2ubuntu2+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-23634.json"}}],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-23634"},{"type":"REPORT","url":"https://github.com/puma/puma/security/advisories/GHSA-rmj8-8hhh-gv5h"},{"type":"REPORT","url":"https://github.com/puma/puma/commit/b70f451fe8abc0cff192c065d549778452e155bb"},{"type":"REPORT","url":"https://groups.google.com/g/ruby-security-ann/c/FkTM-_7zSNA/m/K2RiMJBlBAAJ?utm_medium=email&utm_source=footer&pli=1"},{"type":"REPORT","url":"https://github.com/advisories/GHSA-rmj8-8hhh-gv5h"},{"type":"REPORT","url":"https://github.com/advisories/GHSA-wh98-p28r-vrc9"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6682-1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-23634"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}