BIT-haproxy-2023-0836
Dashboard / Vulnerabilities / BIT-haproxy-2023-0836
Summary:
Details: An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
References: https://git.haproxy.org/?p=haproxy.git%3Ba=commitdiff%3Bh=2e6bf0a, https://www.debian.org/security/2023/dsa-5388, https://nvd.nist.gov/vuln/detail/CVE-2023-0836
Affected packages
Package
Name: haproxy
Purl: pkg:bitnami/haproxy
Affected ranges
Type: SEMVER
Events:
Introduced- 2.1.0
Fixed -2.1.1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
