<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for rubygem-puma</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2024:3644-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-10-16T06:55:11Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-10-16T06:55:11Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-10-16T06:55:11Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for rubygem-puma</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for rubygem-puma fixes the following issues:

- CVE-2024-45614: Prevent underscores from clobbering hyphen headers (bsc#1230848).
- CVE-2024-21647: Fixed DoS when parsing chunked Transfer-Encoding bodies (bsc#1218638).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Image SLES15-SP3-SAP-Azure-LI-BYOS-Production-2024-3644,Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production-2024-3644,Image SLES15-SP3-SAP-BYOS-Azure-2024-3644,Image SLES15-SP3-SAP-BYOS-EC2-HVM-2024-3644,Image SLES15-SP3-SAP-BYOS-GCE-2024-3644,Image SLES15-SP4-SAP-Azure-LI-BYOS-2024-3644,Image SLES15-SP4-SAP-Azure-LI-BYOS-Production-2024-3644,Image SLES15-SP4-SAP-Azure-VLI-BYOS-2024-3644,Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production-2024-3644,Image SLES15-SP4-SAP-BYOS-2024-3644,Image SLES15-SP4-SAP-BYOS-Azure-2024-3644,Image SLES15-SP4-SAP-BYOS-EC2-2024-3644,Image SLES15-SP4-SAP-BYOS-GCE-2024-3644,Image SLES15-SP4-SAP-Hardened-2024-3644,Image SLES15-SP4-SAP-Hardened-Azure-2024-3644,Image SLES15-SP4-SAP-Hardened-BYOS-2024-3644,Image SLES15-SP4-SAP-Hardened-BYOS-Azure-2024-3644,Image SLES15-SP4-SAP-Hardened-BYOS-EC2-2024-3644,Image SLES15-SP4-SAP-Hardened-BYOS-GCE-2024-3644,Image SLES15-SP4-SAP-Hardened-GCE-2024-3644,Image SLES15-SP5-SAP-Azure-3P-2024-3644,Image SLES15-SP5-SAP-Azure-LI-BYOS-2024-3644,Image SLES15-SP5-SAP-Azure-LI-BYOS-Production-2024-3644,Image SLES15-SP5-SAP-Azure-VLI-BYOS-2024-3644,Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production-2024-3644,Image SLES15-SP5-SAP-BYOS-Azure-2024-3644,Image SLES15-SP5-SAP-BYOS-EC2-2024-3644,Image SLES15-SP5-SAP-BYOS-GCE-2024-3644,Image SLES15-SP5-SAP-Hardened-Azure-2024-3644,Image SLES15-SP5-SAP-Hardened-BYOS-Azure-2024-3644,Image SLES15-SP5-SAP-Hardened-BYOS-EC2-2024-3644,Image SLES15-SP5-SAP-Hardened-BYOS-GCE-2024-3644,Image SLES15-SP5-SAP-Hardened-GCE-2024-3644,SUSE-2024-3644,SUSE-SLE-Product-HA-15-SP2-2024-3644,SUSE-SLE-Product-HA-15-SP3-2024-3644,SUSE-SLE-Product-HA-15-SP4-2024-3644,SUSE-SLE-Product-HA-15-SP5-2024-3644,openSUSE-SLE-15.5-2024-3644</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20243644-1/</URL>
      <Description>Link for SUSE-SU-2024:3644-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2024-October/019615.html</URL>
      <Description>E-Mail link for SUSE-SU-2024:3644-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1218638</URL>
      <Description>SUSE Bug 1218638</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1230848</URL>
      <Description>SUSE Bug 1230848</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-21647/</URL>
      <Description>SUSE CVE CVE-2024-21647 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-45614/</URL>
      <Description>SUSE CVE CVE-2024-45614 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-Azure-LI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-Azure-LI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SP3-SAP-Azure-LI-BYOS-Production">Image SLES15-SP3-SAP-Azure-LI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production">Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP3-SAP-BYOS-Azure">Image SLES15-SP3-SAP-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-BYOS-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-BYOS-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP3-SAP-BYOS-EC2-HVM">Image SLES15-SP3-SAP-BYOS-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP3-SAP-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP3-SAP-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP3-SAP-BYOS-GCE">Image SLES15-SP3-SAP-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-Azure-LI-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-Azure-LI-BYOS">
        <FullProductName ProductID="Image SLES15-SP4-SAP-Azure-LI-BYOS">Image SLES15-SP4-SAP-Azure-LI-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-Azure-LI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-Azure-LI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SP4-SAP-Azure-LI-BYOS-Production">Image SLES15-SP4-SAP-Azure-LI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-Azure-VLI-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-Azure-VLI-BYOS">
        <FullProductName ProductID="Image SLES15-SP4-SAP-Azure-VLI-BYOS">Image SLES15-SP4-SAP-Azure-VLI-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production">Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-BYOS">
        <FullProductName ProductID="Image SLES15-SP4-SAP-BYOS">Image SLES15-SP4-SAP-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP4-SAP-BYOS-Azure">Image SLES15-SP4-SAP-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-BYOS-EC2">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-BYOS-EC2">
        <FullProductName ProductID="Image SLES15-SP4-SAP-BYOS-EC2">Image SLES15-SP4-SAP-BYOS-EC2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP4-SAP-BYOS-GCE">Image SLES15-SP4-SAP-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-Hardened">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-Hardened">
        <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened">Image SLES15-SP4-SAP-Hardened</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-Hardened-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-Hardened-Azure">
        <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened-Azure">Image SLES15-SP4-SAP-Hardened-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-Hardened-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-Hardened-BYOS">
        <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened-BYOS">Image SLES15-SP4-SAP-Hardened-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-Hardened-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-Hardened-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened-BYOS-Azure">Image SLES15-SP4-SAP-Hardened-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-Hardened-BYOS-EC2">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-Hardened-BYOS-EC2">
        <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened-BYOS-EC2">Image SLES15-SP4-SAP-Hardened-BYOS-EC2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-Hardened-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-Hardened-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened-BYOS-GCE">Image SLES15-SP4-SAP-Hardened-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP4-SAP-Hardened-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP4-SAP-Hardened-GCE">
        <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened-GCE">Image SLES15-SP4-SAP-Hardened-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-Azure-3P">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-Azure-3P">
        <FullProductName ProductID="Image SLES15-SP5-SAP-Azure-3P">Image SLES15-SP5-SAP-Azure-3P</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-Azure-LI-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-Azure-LI-BYOS">
        <FullProductName ProductID="Image SLES15-SP5-SAP-Azure-LI-BYOS">Image SLES15-SP5-SAP-Azure-LI-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-Azure-LI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-Azure-LI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SP5-SAP-Azure-LI-BYOS-Production">Image SLES15-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-Azure-VLI-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-Azure-VLI-BYOS">
        <FullProductName ProductID="Image SLES15-SP5-SAP-Azure-VLI-BYOS">Image SLES15-SP5-SAP-Azure-VLI-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production">Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP5-SAP-BYOS-Azure">Image SLES15-SP5-SAP-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-BYOS-EC2">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-BYOS-EC2">
        <FullProductName ProductID="Image SLES15-SP5-SAP-BYOS-EC2">Image SLES15-SP5-SAP-BYOS-EC2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP5-SAP-BYOS-GCE">Image SLES15-SP5-SAP-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-Hardened-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-Hardened-Azure">
        <FullProductName ProductID="Image SLES15-SP5-SAP-Hardened-Azure">Image SLES15-SP5-SAP-Hardened-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-Hardened-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-Hardened-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP5-SAP-Hardened-BYOS-Azure">Image SLES15-SP5-SAP-Hardened-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-Hardened-BYOS-EC2">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-Hardened-BYOS-EC2">
        <FullProductName ProductID="Image SLES15-SP5-SAP-Hardened-BYOS-EC2">Image SLES15-SP5-SAP-Hardened-BYOS-EC2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-Hardened-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-Hardened-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP5-SAP-Hardened-BYOS-GCE">Image SLES15-SP5-SAP-Hardened-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP5-SAP-Hardened-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP5-SAP-Hardened-GCE">
        <FullProductName ProductID="Image SLES15-SP5-SAP-Hardened-GCE">Image SLES15-SP5-SAP-Hardened-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Availability Extension 15 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Availability Extension 15 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15 SP2" CPE="cpe:/o:suse:sle-ha:15:sp2">SUSE Linux Enterprise High Availability Extension 15 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Availability Extension 15 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Availability Extension 15 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15 SP3" CPE="cpe:/o:suse:sle-ha:15:sp3">SUSE Linux Enterprise High Availability Extension 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Availability Extension 15 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Availability Extension 15 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15 SP4" CPE="cpe:/o:suse:sle-ha:15:sp4">SUSE Linux Enterprise High Availability Extension 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Availability Extension 15 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Availability Extension 15 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15 SP5" CPE="cpe:/o:suse:sle-ha:15:sp5">SUSE Linux Enterprise High Availability Extension 15 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.5">
      <Branch Type="Product Name" Name="openSUSE Leap 15.5">
        <FullProductName ProductID="openSUSE Leap 15.5" CPE="cpe:/o:opensuse:leap:15.5">openSUSE Leap 15.5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">
      <FullProductName ProductID="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ruby2.5-rubygem-puma-doc-4.3.12-150000.3.15.1">
      <FullProductName ProductID="ruby2.5-rubygem-puma-doc-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-doc-4.3.12-150000.3.15.1</FullProductName>
    </Branch>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SP3-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP3-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP3-SAP-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP3-SAP-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP3-SAP-BYOS-EC2-HVM:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP3-SAP-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP3-SAP-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP3-SAP-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP3-SAP-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-Azure-LI-BYOS">
      <FullProductName ProductID="Image SLES15-SP4-SAP-Azure-LI-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-Azure-LI-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SP4-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-Azure-VLI-BYOS">
      <FullProductName ProductID="Image SLES15-SP4-SAP-Azure-VLI-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-Azure-VLI-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-BYOS">
      <FullProductName ProductID="Image SLES15-SP4-SAP-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP4-SAP-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-BYOS-EC2">
      <FullProductName ProductID="Image SLES15-SP4-SAP-BYOS-EC2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-BYOS-EC2</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP4-SAP-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-Hardened">
      <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-Hardened</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-Hardened-Azure">
      <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-Hardened-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-Hardened-BYOS">
      <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-Hardened-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-Hardened-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-Hardened-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-Hardened-BYOS-EC2">
      <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened-BYOS-EC2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-Hardened-BYOS-EC2</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-Hardened-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-Hardened-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-SAP-Hardened-GCE">
      <FullProductName ProductID="Image SLES15-SP4-SAP-Hardened-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP4-SAP-Hardened-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-Azure-3P">
      <FullProductName ProductID="Image SLES15-SP5-SAP-Azure-3P:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-Azure-3P</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-Azure-LI-BYOS">
      <FullProductName ProductID="Image SLES15-SP5-SAP-Azure-LI-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-Azure-LI-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SP5-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-Azure-VLI-BYOS">
      <FullProductName ProductID="Image SLES15-SP5-SAP-Azure-VLI-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-Azure-VLI-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP5-SAP-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-BYOS-EC2">
      <FullProductName ProductID="Image SLES15-SP5-SAP-BYOS-EC2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-BYOS-EC2</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP5-SAP-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-Hardened-Azure">
      <FullProductName ProductID="Image SLES15-SP5-SAP-Hardened-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-Hardened-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-Hardened-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP5-SAP-Hardened-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-Hardened-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-Hardened-BYOS-EC2">
      <FullProductName ProductID="Image SLES15-SP5-SAP-Hardened-BYOS-EC2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-Hardened-BYOS-EC2</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-Hardened-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP5-SAP-Hardened-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-Hardened-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP5-SAP-Hardened-GCE">
      <FullProductName ProductID="Image SLES15-SP5-SAP-Hardened-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of Image SLES15-SP5-SAP-Hardened-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Availability Extension 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15 SP2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of SUSE Linux Enterprise High Availability Extension 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Availability Extension 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15 SP3:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of SUSE Linux Enterprise High Availability Extension 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Availability Extension 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15 SP4:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of SUSE Linux Enterprise High Availability Extension 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Availability Extension 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise High Availability Extension 15 SP5:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of SUSE Linux Enterprise High Availability Extension 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-4.3.12-150000.3.15.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="ruby2.5-rubygem-puma-doc-4.3.12-150000.3.15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:ruby2.5-rubygem-puma-doc-4.3.12-150000.3.15.1">ruby2.5-rubygem-puma-doc-4.3.12-150000.3.15.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Puma is a web server for Ruby/Rack applications built for parallelism. Prior to version 6.4.2, puma exhibited incorrect behavior when parsing chunked transfer encoding bodies in a way that allowed HTTP request smuggling. Fixed versions limits the size of chunk extensions. Without this limit, an attacker could cause unbounded resource (CPU, network bandwidth) consumption. This vulnerability has been fixed in versions 6.4.2 and 5.6.8.

</Note>
    </Notes>
    <CVE>CVE-2024-21647</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES15-SP3-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-BYOS-EC2-HVM:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Azure-LI-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Azure-VLI-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-BYOS-EC2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened-BYOS-EC2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Azure-3P:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Azure-LI-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Azure-VLI-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-BYOS-EC2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Hardened-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Hardened-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Hardened-BYOS-EC2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Hardened-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Hardened-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15 SP2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15 SP3:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15 SP4:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15 SP5:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>openSUSE Leap 15.5:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>openSUSE Leap 15.5:ruby2.5-rubygem-puma-doc-4.3.12-150000.3.15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20243644-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-21647.html</URL>
        <Description>CVE-2024-21647</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1218638</URL>
        <Description>SUSE Bug 1218638</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwarded-For) by providing a underscore version of the same header (X-Forwarded_For). Any users relying on proxy set variables is affected. v6.4.3/v5.6.9 now discards any headers using underscores if the non-underscore version also exists. Effectively, allowing the proxy defined headers to always win. Users are advised to upgrade. Nginx has a underscores_in_headers configuration variable to discard these headers at the proxy level as a mitigation. Any users that are implicitly trusting the proxy defined headers for security should immediately cease doing so until upgraded to the fixed versions.</Note>
    </Notes>
    <CVE>CVE-2024-45614</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES15-SP3-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-BYOS-EC2-HVM:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP3-SAP-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Azure-LI-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Azure-VLI-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-BYOS-EC2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened-BYOS-EC2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP4-SAP-Hardened:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Azure-3P:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Azure-LI-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Azure-VLI-BYOS:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-BYOS-EC2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Hardened-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Hardened-BYOS-Azure:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Hardened-BYOS-EC2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Hardened-BYOS-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>Image SLES15-SP5-SAP-Hardened-GCE:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15 SP2:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15 SP3:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15 SP4:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Availability Extension 15 SP5:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>openSUSE Leap 15.5:ruby2.5-rubygem-puma-4.3.12-150000.3.15.1</ProductID>
        <ProductID>openSUSE Leap 15.5:ruby2.5-rubygem-puma-doc-4.3.12-150000.3.15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20243644-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-45614.html</URL>
        <Description>CVE-2024-45614</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1230848</URL>
        <Description>SUSE Bug 1230848</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
