CVE-2021-41136 log

Source
Severity Low
Remote Yes
Type Unknown
Description
Using puma with a proxy which forwards LF characters as line endings could allow HTTP request smuggling. Puma is only aware of a single proxy server which has this behavior.
Group Package Affected Fixed Severity Status Ticket
AVG-2764 ruby-puma 5.6.3-1 5.6.4-1 High Unknown
References
https://github.com/puma/puma/commit/acdc3ae571dfae0e045cf09a295280127db65c7f
https://github.com/puma/puma/security/advisories/GHSA-48w2-rm65-62xx