Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-45539


HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.


Published

2023-11-28T20:15:07.817

Last Modified

2024-11-21T08:26:56.747

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.2 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-116

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application haproxy haproxy < 2.8.2 Yes

References