cbcvebase.
CVE-2023-0056
published 2023-03-23

CVE-2023-0056: An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianhaproxy< haproxy 2.6.8-1 (bookworm)haproxy 2.6.8-1 (bookworm)
fedoraprojectextra_packages_for_enterprise_linux
fedoraprojectfedora
fedoraprojectfedora
haproxyhaproxy>= 0 < 2.2.9-2+deb11u42.2.9-2+deb11u4
haproxyhaproxy>= 0 < 2.6.8-12.6.8-1
haproxyhaproxy>= 0 < 2.6.8-12.6.8-1
haproxyhaproxy>= 0 < 2.6.8-12.6.8-1
redhatceph_storage
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform_for_ibm_linuxone
redhatopenshift_container_platform_for_ibm_linuxone
redhatopenshift_container_platform_for_ibm_linuxone
redhatopenshift_container_platform_for_power
redhatopenshift_container_platform_for_power
redhatopenshift_container_platform_for_power
redhatopenshift_container_platform_ibm_z_systems
redhatopenshift_container_platform_ibm_z_systems
redhatopenshift_container_platform_ibm_z_systems

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM