Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwmg-q4wv-f75h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An integer overflow exists in HAProxy 2.0 through 2.5 in the htx_add_header() can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

An integer overflow exists in HAProxy 2.0 through 2.5 in the htx_add_header() can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

EPSS

Процентиль: 100%
0.92854
Критический

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

CVSS3: 7.5
redhat
больше 4 лет назад

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

CVSS3: 7.5
nvd
больше 4 лет назад

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

CVSS3: 7.5
debian
больше 4 лет назад

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_heade ...

suse-cvrf
больше 4 лет назад

Security update for haproxy

EPSS

Процентиль: 100%
0.92854
Критический

Дефекты

CWE-190