cbcvebase.
CVE-2018-11469
published 2018-05-25

CVE-2018-11469: Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve…

PriorityP434medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
3.06%
86.2th percentile
Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check_request_for_cacheability function.

Affected

7 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianhaproxy< haproxy 1.8.9-2 (bookworm)haproxy 1.8.9-2 (bookworm)
haproxyhaproxy>= 0 < 1.8.9-21.8.9-2
haproxyhaproxy>= 0 < 1.8.9-21.8.9-2
haproxyhaproxy>= 0 < 1.8.9-21.8.9-2
haproxyhaproxy>= 0 < 1.8.9-21.8.9-2
haproxyhaproxy1.8.0 – 1.8.9

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.