Back

HIGH

haproxy: data leak via fcgi requests

Published Mar 29, 2023

Description

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Mar 29, 2023
Updated Feb 18, 2025
Reserved Feb 14, 2023

CISA Vulnrichment

Updated Feb 18, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Dec 9, 2022
Bugzilla 2180746

ENISA EUVD

Assigner redhat
Published Mar 29, 2023
Updated Feb 18, 2025

GitHub

No data