Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11787
HistoryJan 15, 2019 - 9:07 a.m.

Information Disclosure

2019-01-1509:07:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

EPSS

0.003

Percentile

71.4%

haproxy is vulnerable to information disclosure attacks. The vulnerability exists as the buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.