Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0711

Опубликовано: 23 фев. 2022
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

Отчет

This issue was introduced in HAProxy 1.9 with the Native HTTP Representation (HTX). Red Hat Enterprise Linux 6, 7, 8 and Red Hat Software Collections are not affected by this flaw, as they ship older versions of haproxy which do not include support for HTX.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6haproxyNot affected
Red Hat Enterprise Linux 7haproxyNot affected
Red Hat Enterprise Linux 8haproxyNot affected
Red Hat Enterprise Linux 9haproxyNot affected
Red Hat OpenShift Container Platform 3.11haproxyNot affected
Red Hat Software Collectionsrh-haproxy18-haproxyNot affected
Red Hat OpenShift Container Platform 4.6haproxyFixedRHSA-2022:162004.05.2022
Red Hat OpenShift Container Platform 4.7haproxyFixedRHSA-2022:133620.04.2022
Red Hat OpenShift Container Platform 4.8haproxyFixedRHSA-2022:115311.04.2022
Red Hat OpenShift Container Platform 4.9haproxyFixedRHSA-2022:102129.03.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2053666haproxy: Denial of service via set-cookie2 header

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

CVSS3: 7.5
nvd
почти 4 года назад

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

CVSS3: 7.5
msrc
почти 4 года назад

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

CVSS3: 7.5
debian
почти 4 года назад

A flaw was found in the way HAProxy processed HTTP responses containin ...

suse-cvrf
больше 3 лет назад

Security update for haproxy

7.5 High

CVSS3