Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-0056

Опубликовано: 23 мар. 2023
Источник: debian
EPSS Низкий

Описание

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
haproxyfixed2.6.8-1package
haproxynot-affectedbusterpackage

Примечания

  • https://github.com/haproxy/haproxy/issues/1972

  • https://git.haproxy.org/?p=haproxy-2.6.git;a=commit;h=84f5cba24f59b1c8339bb38323fcb01f434ba8e5 (v2.6.8)

  • https://git.haproxy.org/?p=haproxy-2.2.git;a=commit;h=038a7e8aeb1c5b90c18c55d2bcfb3aaa476bce89 (v2.2.27)

EPSS

Процентиль: 36%
0.00148
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

CVSS3: 4.3
redhat
больше 2 лет назад

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

CVSS3: 6.5
nvd
около 2 лет назад

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

suse-cvrf
больше 2 лет назад

Security update for haproxy

CVSS3: 6.5
github
около 2 лет назад

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

EPSS

Процентиль: 36%
0.00148
Низкий
Уязвимость CVE-2023-0056