HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade haproxy | Apr 21, 2023 | Feb 14, 2023 |
| Amazon Linux Ami 2 | — | Upgrade haproxy2-debuginfoUpgrade haproxy2 | Sep 28, 2023 | Feb 14, 2023 |
| Centos_linux | — | Upgrade haproxy-debugsourceUpgrade haproxyUpgrade haproxy-debuginfo | Apr 12, 2023 | Feb 14, 2023 |
| Debian | — | Upgrade haproxy | Feb 16, 2023 | Feb 14, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade haproxy | May 18, 2023 | Feb 14, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade haproxy | Jul 5, 2023 | Feb 14, 2023 |
| Huawei Euleros 2_0_sp9 | — | Upgrade haproxy | May 10, 2023 | Feb 14, 2023 |
| Oracle_linux | — | Upgrade haproxy | Apr 12, 2023 | Feb 14, 2023 |
| Redhat Openshift | — | Upgrade haproxy | Mar 22, 2023 | Feb 14, 2023 |
| Redhat_linux | — | Upgrade haproxy-debuginfoUpgrade haproxy-debugsourceUpgrade haproxy | Apr 12, 2023 | Feb 14, 2023 |
| Suse | — | Upgrade haproxy | Feb 16, 2023 | Feb 14, 2023 |
| Ubuntu | — | Upgrade haproxyUpgrade haproxy (Ubuntu Pro) | Mar 22, 2023 | Feb 14, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub