Lucene search

K
ubuntuUbuntuUSN-6294-1
HistoryAug 16, 2023 - 12:00 a.m.

HAProxy vulnerability

2023-08-1600:00:00
ubuntu.com
28
ubuntu
haproxy
vulnerability
payload manipulation
content-length headers
bypass restrictions

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

7.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.0%

Releases

  • Ubuntu 23.04
  • Ubuntu 22.04 LTS

Packages

  • haproxy - fast and reliable load balancing reverse proxy

Details

Ben Kallus discovered that HAProxy incorrectly handled empty Content-Length
headers. A remote attacker could possibly use this issue to manipulate the
payload and bypass certain restrictions.

OSVersionArchitecturePackageVersionFilename
Ubuntu23.04noarchhaproxy< 2.6.9-1ubuntu1.1UNKNOWN
Ubuntu23.04noarchhaproxy-dbgsym< 2.6.9-1ubuntu1.1UNKNOWN
Ubuntu23.04noarchhaproxy-doc< 2.6.9-1ubuntu1.1UNKNOWN
Ubuntu23.04noarchvim-haproxy< 2.6.9-1ubuntu1.1UNKNOWN
Ubuntu22.04noarchhaproxy< 2.4.22-0ubuntu0.22.04.2UNKNOWN
Ubuntu22.04noarchhaproxy-dbgsym< 2.4.22-0ubuntu0.22.04.2UNKNOWN
Ubuntu22.04noarchhaproxy-doc< 2.4.22-0ubuntu0.22.04.2UNKNOWN
Ubuntu22.04noarchvim-haproxy< 2.4.22-0ubuntu0.22.04.2UNKNOWN

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

7.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.0%