Known vulnerabilities in puma (Debian package) 3.12.0-2+deb10u2
Vendor:
Debian
Software:
puma (Debian package)
Version:
3.12.0-2+deb10u2
Software CPE:
cpe:2.3:o:debian:puma_debian_package:*:*:*:*:*:debian_linux:*:*
Website:
https://www.debian.org/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Vulnerabilities by Severity
5.3.2-3+b1
5.5.2-2+b1
5.6.4-1+b1
5.6.5-2+b1
5.6.7-1+b1
6.4.2-4+b1
6.4.2-4+b2
6.4.3-2+b1
6.6.0-2+b1
3.6.0-1+deb9u1
3.6.0-1+deb9u2
3.12.0-2+deb10u3
4.3.8-1
4.3.8-1+deb11u3
5.2.2-1
5.2.2-2
5.3.2-1
5.3.2-2
5.3.2-3
5.5.2-1
5.5.2-2
5.6.4-1
5.6.5-1
5.6.5-2
5.6.5-3
5.6.5-3+deb12u1
5.6.5-4
5.6.7-1
6.0.2-1
6.4.0-1
6.4.0-2
6.4.0-3
6.4.0-4
6.4.2-1
6.4.2-2
6.4.2-3
6.4.2-4
6.4.2-5
6.4.2-6
6.4.3-1
6.4.3-2
6.4.3-3
6.6.0-1
6.6.0-2
6.6.0-3
6.6.0-4
4.3.8-1+deb11u2
4.3.8-1+deb11u1
4.3.6-1+b1
3.12.0-2+deb10u2
4.3.6
4.3.6-1
4.3.3-3
4.3.3-2
3.11.3-1+b1
3.12.0-2+b1
3.12.0-4+b1
4.3.3
4.3.1
3.12.4
3.12.4-1+b1
3.12.0
3.6.0
3.12.0-2+deb10u1
3.12.4-1
4.3.3-1
3.12.0-4
4.3.1-1
3.12.0-3
3.12.0-1
3.12.0-2
3.11.3-1
3.6.0-1
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU63635 - Exposure of sensitive information to an unauthorized actor CVE-2022-23634 |
CWE-200 | Medium | 4.3.8-1+deb11u2 | 25.05.2022 |
SB2022052518 SB2022052603 SB2024030762 and 10 more |
||
| #VU63634 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2021-41136 |
CWE-444 | Medium | 4.3.8-1+deb11u2 | 25.05.2022 |
SB2022052517 SB2022052603 SB2021111919 and 4 more |
||
| #VU61798 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-24790 |
CWE-444 | Medium | 4.3.8-1+deb11u2 | 01.04.2022 |
SB2022040112 SB2022052603 SB2022092241 and 12 more |