Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-45539

Опубликовано: 28 нояб. 2023
Источник: redhat
CVSS3: 5.3

Описание

HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 5haproxyAffected
Red Hat Enterprise Linux 8haproxyFixedRHSA-2024:884905.11.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupporthaproxyFixedRHSA-2024:994519.11.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupporthaproxyFixedRHSA-2024:1027126.11.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicehaproxyFixedRHSA-2024:1027126.11.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionshaproxyFixedRHSA-2024:1027126.11.2024
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupporthaproxyFixedRHSA-2024:887405.11.2024
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicehaproxyFixedRHSA-2024:887405.11.2024
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionshaproxyFixedRHSA-2024:887405.11.2024
Red Hat Enterprise Linux 8.8 Extended Update SupporthaproxyFixedRHSA-2024:1026726.11.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-288
https://bugzilla.redhat.com/show_bug.cgi?id=2253037haproxy: untrimmed URI fragments may lead to exposure of confidential data on static servers

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 1 года назад

HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.

CVSS3: 8.2
nvd
больше 1 года назад

HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.

CVSS3: 8.2
debian
больше 1 года назад

HAProxy before 2.8.2 accepts # as part of the URI component, which mig ...

suse-cvrf
больше 1 года назад

Security update for haproxy

suse-cvrf
больше 1 года назад

Security update for haproxy

5.3 Medium

CVSS3