haproxy: data leak via fcgi requests
Published Mar 29, 2023
7.5
HIGHCVSS 3.1
EPSS 1.20%
Description
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
Affected products
- Vendor n/a Product HAProxy Defaultunknown
Affected
- HAProxy 2.8, HAProxy 2.7.1, HAProxy 2.6.8, HAProxy 2.5.11, HAProxy 2.4.21, HAProxy 2.2.27
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | HAProxy | unknown | Affected
|
No data.
Red Hat Enterprise Linux 9
haproxy-0:2.4.22-1.el9
Fixed · RHSA-2023:6496
Red Hat Ceph Storage 5
haproxy
Affected
Red Hat Enterprise Linux 7
haproxy
Out of support scope
Red Hat Enterprise Linux 8
haproxy
Not affected
Red Hat OpenShift Container Platform 3.11
haproxy
Out of support scope
Red Hat OpenShift Container Platform 4
haproxy
Will not fix
Red Hat Software Collections
rh-haproxy18-haproxy
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | haproxy-0:2.4.22-1.el9 | Fixed | RHSA-2023:6496 |
| Red Hat Ceph Storage 5 | haproxy | Affected | n/a |
| Red Hat Enterprise Linux 7 | haproxy | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | haproxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | haproxy | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | haproxy | Will not fix | n/a |
| Red Hat Software Collections | rh-haproxy18-haproxy | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2023-0836 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2180746 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12837 Advisory
- https://git.haproxy.org/?p=haproxy.git%3Ba=commitdiff%3Bh=2e6bf0a
- https://git.haproxy.org/?p=haproxy.git;a=commitdiff;h=2e6bf0a
- https://nvd.nist.gov/vuln/detail/CVE-2023-0836
- https://www.cve.org/CVERecord?id=CVE-2023-0836
- https://www.debian.org/security/2023/dsa-5388 vendor-advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data