An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade haproxy | Nov 16, 2023 | Mar 29, 2023 |
| Amazon Linux Ami 2 | — | Upgrade haproxy2Upgrade haproxy2-debuginfo | Sep 28, 2023 | Mar 29, 2023 |
| Centos_linux | — | Upgrade haproxy-debuginfoUpgrade haproxy-debugsourceUpgrade haproxy | Nov 8, 2023 | Mar 29, 2023 |
| Debian | — | Upgrade haproxy | Apr 17, 2023 | Mar 29, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade haproxy | Jan 10, 2024 | Mar 29, 2023 |
| Oracle_linux | — | Upgrade haproxy | Nov 16, 2023 | Dec 9, 2022 |
| Redhat_linux | — | Upgrade haproxy-debugsourceNo solution existsUpgrade haproxyUpgrade haproxy-debuginfo | Nov 8, 2023 | Mar 29, 2023 |
| Ubuntu | — | Upgrade haproxy | Apr 10, 2023 | Mar 29, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 29, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub