vulnerability

Amazon Linux AMI 2: CVE-2023-0056: Security patch for haproxy2 (ALASHAPROXY2-2023-004)

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:C)
Published
Mar 23, 2023
Added
Sep 28, 2023
Modified
Jan 28, 2025

Description

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

Solution(s)

amazon-linux-ami-2-upgrade-haproxy2amazon-linux-ami-2-upgrade-haproxy2-debuginfo
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.