Описание
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
Ссылки
- PatchVendor Advisory
- PatchThird Party Advisory
- ExploitMitigationThird Party Advisory
- Third Party Advisory
- PatchVendor Advisory
- PatchThird Party Advisory
- ExploitMitigationThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_heade ...
EPSS
7.5 High
CVSS3
5 Medium
CVSS2