Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-0836

Опубликовано: 09 дек. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.

A flaw was found in HAProxy, which could allow a remote attacker to obtain sensitive information caused by improper initialization when encoding the FCGI_BEGIN_REQUEST record. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information and use this information to launch further attacks against the affected system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 5haproxyAffected
Red Hat Enterprise Linux 7haproxyOut of support scope
Red Hat Enterprise Linux 8haproxyNot affected
Red Hat OpenShift Container Platform 3.11haproxyOut of support scope
Red Hat OpenShift Container Platform 4haproxyWill not fix
Red Hat Software Collectionsrh-haproxy18-haproxyWill not fix
Red Hat Enterprise Linux 9haproxyFixedRHSA-2023:649607.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-459
https://bugzilla.redhat.com/show_bug.cgi?id=2180746haproxy: data leak via fcgi requests

EPSS

Процентиль: 65%
0.01201
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.

CVSS3: 7.5
nvd
больше 3 лет назад

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.

CVSS3: 7.5
debian
больше 3 лет назад

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 b ...

CVSS3: 7.5
github
больше 3 лет назад

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.

oracle-oval
больше 2 лет назад

ELSA-2023-6496: haproxy security and bug fix update (MODERATE)

EPSS

Процентиль: 65%
0.01201
Низкий

7.5 High

CVSS3