Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-0836


An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.


Published

2023-03-29T21:15:07.950

Last Modified

2025-02-18T17:15:15.600

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-200
  • Type: Secondary
    CWE-459
  • Type: Secondary
    CWE-459

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application haproxy haproxy < 2.2.27 Yes
Application haproxy haproxy ≤ 2.4.21 Yes
Application haproxy haproxy ≤ 2.5.11 Yes
Application haproxy haproxy ≤ 2.6.8 Yes
Application haproxy haproxy 2.1.0 Yes
Application haproxy haproxy 2.3.0 Yes
Application haproxy haproxy 2.7.0 Yes

References