ALSA-2024:1142
Dashboard / Vulnerabilities / ALSA-2024:1142
Summary: Moderate: haproxy security update
Details: The haproxy packages provide a reliable, high-performance network load balancer for TCP and HTTP-based applications. Security Fix(es): * haproxy: Proxy forwards malformed empty Content-Length headers (CVE-2023-40225) * haproxy: untrimmed URI fragments may lead to exposure of confidential data on static servers (CVE-2023-45539) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2024:1142, https://access.redhat.com/security/cve/CVE-2023-40225, https://access.redhat.com/security/cve/CVE-2023-45539, https://bugzilla.redhat.com/2231370, https://bugzilla.redhat.com/2253037, https://errata.almalinux.org/9/ALSA-2024-1142.html
Affected packages
Package
Name: haproxy
Purl: pkg:rpm/almalinux/haproxy
Affected ranges
Type: ECOSYSTEM
Events:
