Vulnerability CVE-2023-25950: Information

Description

HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a denial-of-service (DoS) condition.

Severity: HIGH (7.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Published: April 11, 2023
Modified: Nov. 7, 2023
Error type identifier: CWE-444

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
haproxysisyphus2.6.8-alt12.8.9-alt1ALT-PU-2023-1134-1314210Fixed
haproxysisyphus_e2k2.6.8-alt12.8.9-alt1ALT-PU-2023-2366-1-Fixed
haproxyp102.6.13-alt1.12.6.17-alt1ALT-PU-2023-1942-1322243Fixed
haproxyp10_e2k2.6.13-alt1.12.6.17-alt1ALT-PU-2023-3789-1-Fixed
haproxyc10f12.6.15-alt12.6.15-alt1ALT-PU-2023-5064-2327661Fixed
haproxyc9f22.8.2-alt12.8.2-alt1ALT-PU-2023-5100-3327695Fixed
haproxyp112.6.8-alt12.8.9-alt1ALT-PU-2023-1134-1314210Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:haproxy:haproxy:2.7.0:*:*:*:*:*:*:*

      cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*
      Start including
      2.6.1
      End including
      2.6.7