Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-11469

Опубликовано: 25 мая 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 5.9

Описание

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check_request_for_cacheability function.

РелизСтатусПримечание
artful

not-affected

bionic

released

1.8.8-1ubuntu0.1
devel

released

1.8.9-2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
esm-infra/bionic

released

1.8.8-1ubuntu0.1
esm-infra/xenial

not-affected

precise/esm

DNE

trusty

not-affected

trusty/esm

DNE

trusty was not-affected
upstream

needs-triage

Показывать по

4.3 Medium

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 7 лет назад

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check_request_for_cacheability function.

CVSS3: 5.9
nvd
больше 7 лет назад

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check_request_for_cacheability function.

CVSS3: 5.9
debian
больше 7 лет назад

Incorrect caching of responses to requests including an Authorization ...

CVSS3: 5.9
github
больше 3 лет назад

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check_request_for_cacheability function.

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость функции check_request_for_cacheability серверного программного обеспечения HAProxy, позволяющая нарушителю раскрыть защищаемую информацию

4.3 Medium

CVSS2

5.9 Medium

CVSS3