Описание
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | haproxy | Out of support scope | ||
Red Hat Enterprise Linux 8 | haproxy | Not affected | ||
Red Hat OpenShift Container Platform 3.11 | haproxy | Out of support scope | ||
Red Hat Software Collections | rh-haproxy18-haproxy | Will not fix | ||
Red Hat Ceph Storage 5.3 | rhceph/rhceph-haproxy-rhel8 | Fixed | RHSA-2024:0746 | 08.02.2024 |
Red Hat Enterprise Linux 9 | haproxy | Fixed | RHSA-2023:1696 | 11.04.2023 |
Red Hat Enterprise Linux 9.0 Extended Update Support | haproxy | Fixed | RHSA-2023:1978 | 25.04.2023 |
Red Hat OpenShift Container Platform 4.10 | haproxy | Fixed | RHBA-2023:0898 | 01.03.2023 |
Red Hat OpenShift Container Platform 4.11 | haproxy | Fixed | RHBA-2023:0773 | 21.02.2023 |
Red Hat OpenShift Container Platform 4.12 | haproxy | Fixed | RHSA-2023:0727 | 16.02.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
An uncontrolled resource consumption vulnerability was discovered in H ...
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
EPSS
4.3 Medium
CVSS3