Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-45506

Опубликовано: 04 сент. 2024
Источник: debian
EPSS Низкий

Описание

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
haproxyfixed2.9.10-1package
haproxynot-affectedbookwormpackage
haproxynot-affectedbullseyepackage

Примечания

  • http://git.haproxy.org/?p=haproxy-2.9.git;a=commit;h=c6bc43e9ac18f122f9dee22df47ab1b7ef57b429 (v2.9.10)

  • http://git.haproxy.org/?p=haproxy-3.0.git;a=commit;h=c725db17e8416ffb3c1537aea756356228ce5e3c (v3.0.4)

EPSS

Процентиль: 42%
0.00192
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.

CVSS3: 7.5
redhat
10 месяцев назад

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.

CVSS3: 7.5
nvd
10 месяцев назад

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.

CVSS3: 7.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.5
github
10 месяцев назад

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service.

EPSS

Процентиль: 42%
0.00192
Низкий