It was discovered that Puma incorrectly handled parsing certain headers. A remote attacker could possibly use this issue to overwrite header values set by intermediate proxies by providing duplicate headers containing underscore characters.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "puma", "binary_version": "6.4.2-4ubuntu4.3" }, { "binary_name": "puma-dbgsym", "binary_version": "6.4.2-4ubuntu4.3" } ] }