Description
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5388-1 | haproxy security update |
Ubuntu USN |
USN-5994-1 | HAProxy vulnerability |
References
History
Tue, 18 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-18T16:42:03.756Z
Reserved: 2023-02-14T00:00:00.000Z
Link: CVE-2023-0836
Updated: 2024-08-02T05:24:34.530Z
Status : Modified
Published: 2023-03-29T21:15:07.950
Modified: 2025-02-18T17:15:15.600
Link: CVE-2023-0836
OpenCVE Enrichment
No data.
Debian DSA
Ubuntu USN