CVE-2023-0056

Severity
6.5MEDIUM
EPSS
0.2%
top 58.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23

Description

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

Debianhaproxy< 2.2.9-2+deb11u4+3
CVEListV5haproxyunknown

Also affects: Openshift Container Platform 4.10, 4.11, 4.12, Fedora 36, 37

🔴Vulnerability Details

3
GHSA
GHSA-43q4-pf55-3xhc: An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service2023-03-23
OSV
CVE-2023-0056: An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service2023-03-23
CVEList
CVE-2023-0056: An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service2023-03-23

📋Vendor Advisories

3
Ubuntu
HAProxy vulnerability2023-01-23
Debian
CVE-2023-0056: haproxy - An uncontrolled resource consumption vulnerability was discovered in HAProxy whi...2023
Red Hat
haproxy: segfault DoS2022-12-21