Описание
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | code not present |
| devel | released | 2.2.9-2ubuntu2 |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | code not present |
| esm-infra/focal | released | 2.0.13-2ubuntu0.3 |
| esm-infra/xenial | not-affected | code not present |
| focal | released | 2.0.13-2ubuntu0.3 |
| hirsute | released | 2.2.9-1ubuntu0.2 |
| impish | released | 2.2.9-2ubuntu2 |
| jammy | released | 2.2.9-2ubuntu2 |
Показывать по
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_heade ...
EPSS
5 Medium
CVSS2
7.5 High
CVSS3