Описание
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
A flaw was found in HAProxy. This vulnerability, stemming from a missing length check in the NEW_TOKEN format, could allow a remote attacker to cause a low impact on data integrity and availability. This means an attacker might be able to subtly alter data or temporarily disrupt the service.
Отчет
This Moderate impact vulnerability in HAProxy stems from a missing length check in the NEW_TOKEN format, which could lead to data integrity and availability issues. The high attack complexity required for exploitation reduces the immediate risk in typical Red Hat deployments.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 5 | haproxy | Fix deferred | ||
| Red Hat Ceph Storage 5 | rhceph/rhceph-haproxy-rhel8 | Fix deferred | ||
| Red Hat Ceph Storage 6 | rhceph/rhceph-haproxy-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 7 | rhceph/rhceph-haproxy-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 8 | rhceph/rhceph-haproxy-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 9 | rhceph-ci/haproxy | Fix deferred | ||
| Red Hat Ceph Storage 9 | rhceph/rhceph-haproxy-rhel10 | Fix deferred | ||
| Red Hat Ceph Storage 9 | rhceph/rhceph-haproxy-rhel9 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | haproxy | Fix deferred | ||
| Red Hat Enterprise Linux 7 | haproxy | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
4.8 Medium
CVSS3
Связанные уязвимости
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length ...
EPSS
4.8 Medium
CVSS3