cbcvebase.
CVE-2022-0711
published 2022-03-02

CVE-2022-0711: A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianhaproxy< haproxy 2.4.13-1 (bookworm)haproxy 2.4.13-1 (bookworm)
haproxyhaproxy
haproxyhaproxy>= 0 < 2.2.9-2+deb11u32.2.9-2+deb11u3
haproxyhaproxy>= 0 < 2.4.13-12.4.13-1
haproxyhaproxy>= 0 < 2.4.13-12.4.13-1
haproxyhaproxy>= 0 < 2.4.13-12.4.13-1
haproxyhaproxy>= 2.2.0 < 2.2.212.2.21
haproxyhaproxy>= 2.3.0 < 2.3.182.3.18
haproxyhaproxy>= 2.4.0 < 2.4.132.4.13
msrccbl2_haproxy_2.4.13-1_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux
redhatopenshift_container_platform

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH