UBUNTU-CVE-2023-45539
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-45539
UBUNTU-CVE-2023-45539
Summary:
Details: HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.
References: https://ubuntu.com/security/CVE-2023-45539, https://lists.w3.org/Archives/Public/ietf-http-wg/2023JulSep/0070.html, https://www.mail-archive.com/haproxy%40formilux.org/msg43861.html, https://ubuntu.com/security/notices/USN-6530-1, https://www.cve.org/CVERecord?id=CVE-2023-45539, https://ubuntu.com/security/notices/USN-6530-2
Affected packages
Package
Name: haproxy
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
