Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0711

Опубликовано: 23 фев. 2022
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

Отчет

This issue was introduced in HAProxy 1.9 with the Native HTTP Representation (HTX). Red Hat Enterprise Linux 6, 7, 8 and Red Hat Software Collections are not affected by this flaw, as they ship older versions of haproxy which do not include support for HTX.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6haproxyNot affected
Red Hat Enterprise Linux 7haproxyNot affected
Red Hat Enterprise Linux 8haproxyNot affected
Red Hat Enterprise Linux 9haproxyNot affected
Red Hat OpenShift Container Platform 3.11haproxyNot affected
Red Hat Software Collectionsrh-haproxy18-haproxyNot affected
Red Hat OpenShift Container Platform 4.6haproxyFixedRHSA-2022:162004.05.2022
Red Hat OpenShift Container Platform 4.7haproxyFixedRHSA-2022:133620.04.2022
Red Hat OpenShift Container Platform 4.8haproxyFixedRHSA-2022:115311.04.2022
Red Hat OpenShift Container Platform 4.9haproxyFixedRHSA-2022:102129.03.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2053666haproxy: Denial of service via set-cookie2 header

EPSS

Процентиль: 97%
0.16563
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

CVSS3: 7.5
nvd
больше 4 лет назад

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

CVSS3: 7.5
msrc
больше 4 лет назад

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

CVSS3: 7.5
debian
больше 4 лет назад

A flaw was found in the way HAProxy processed HTTP responses containin ...

suse-cvrf
около 4 лет назад

Security update for haproxy

EPSS

Процентиль: 97%
0.16563
Средний

7.5 High

CVSS3