CVE-2023-0056
published 2023-03-23CVE-2023-0056: An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.83%
76.5th percentile
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | haproxy | < haproxy 2.6.8-1 (bookworm) | haproxy 2.6.8-1 (bookworm) |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| haproxy | haproxy | >= 0 < 2.2.9-2+deb11u4 | 2.2.9-2+deb11u4 |
| haproxy | haproxy | >= 0 < 2.6.8-1 | 2.6.8-1 |
| haproxy | haproxy | >= 0 < 2.6.8-1 | 2.6.8-1 |
| haproxy | haproxy | >= 0 < 2.6.8-1 | 2.6.8-1 |
| redhat | ceph_storage | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform_for_ibm_linuxone | — | — |
| redhat | openshift_container_platform_for_ibm_linuxone | — | — |
| redhat | openshift_container_platform_for_ibm_linuxone | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-43q4-pf55-3xhc: An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service
ghsa_unreviewed·2023-03-23
CVE-2023-0056 [MEDIUM] CWE-400 GHSA-43q4-pf55-3xhc: An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
OSV
CVE-2023-0056: An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service
osv·2023-03-23·CVSS 6.5
CVE-2023-0056 [MEDIUM] CVE-2023-0056: An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Ubuntu
HAProxy vulnerability
vendor_ubuntu·2023-01-23
CVE-2023-0056 HAProxy vulnerability
Title: HAProxy vulnerability
Summary: HAProxy could be made to stop responding if it received specially crafted
network traffic.
It was discovered that HAProxy incorrectly handled certain messages. A
remote attacker could possibly use this issue to cause HAProxy to stop
responding, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2023-0056: haproxy - An uncontrolled resource consumption vulnerability was discovered in HAProxy whi...
vendor_debian·2023·CVSS 6.5
CVE-2023-0056 [MEDIUM] CVE-2023-0056: haproxy - An uncontrolled resource consumption vulnerability was discovered in HAProxy whi...
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Scope: local
bookworm: resolved (fixed in 2.6.8-1)
bullseye: resolved (fixed in 2.2.9-2+deb11u4)
forky: resolved (fixed in 2.6.8-1)
sid: resolved (fixed in 2.6.8-1)
trixie: resolved (fixed in 2.6.8-1)
Red Hat
haproxy: segfault DoS
vendor_redhat·2022-12-21·CVSS 6.5
CVE-2023-0056 [MEDIUM] CWE-400 haproxy: segfault DoS
haproxy: segfault DoS
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Package: haproxy (Red Hat Enterprise Linux 7) - Out of support scope
Package: haproxy (Red Hat Enterprise Linux 8) - Not affected
Package: haproxy (Red Hat OpenShift Container Platform 3.11) - Out of support scope
Package: rh-ha
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-23
Published