Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:42363
HistoryAug 06, 2023 - 7:24 p.m.

Information Disclosure

2023-08-0619:24:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
haproxy
information disclosure
vulnerability
gitlab
fcgi_begin_request
record
exploit
sensitive information
session id

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

52.3%

haproxy is vulnerable to an Information Disclosure. The vulnerability occurs because GitLab does not properly sanitize the FCGI_BEGIN_REQUEST record. An attacker can exploit this vulnerability by sending a malicious request to GitLab that contains a crafted FCGI_BEGIN_REQUEST record. This will cause GitLab to leak sensitive information, such as the session ID, to the attacker.

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

52.3%