Описание
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 3.2.9-1ubuntu2 |
| esm-infra-legacy/xenial | not-affected | code not present |
| esm-infra/bionic | not-affected | code not present |
| esm-infra/focal | not-affected | code not present |
| esm-infra/xenial | not-affected | code not present |
| jammy | not-affected | code not present |
| noble | not-affected | code not present |
| questing | released | 3.0.12-0ubuntu0.25.10.3 |
| upstream | released | 3.0.16, 3.2.12 |
Показывать по
EPSS
4.8 Medium
CVSS3
Связанные уязвимости
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length ...
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.
EPSS
4.8 Medium
CVSS3