CVE-2023-0836
published 2023-03-29CVE-2023-0836: An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.20%
64.7th percentile
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | haproxy | < haproxy 2.6.8-1 (bookworm) | haproxy 2.6.8-1 (bookworm) |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | >= 0 < 2.2.9-2+deb11u5 | 2.2.9-2+deb11u5 |
| haproxy | haproxy | >= 0 < 2.6.8-1 | 2.6.8-1 |
| haproxy | haproxy | >= 0 < 2.6.8-1 | 2.6.8-1 |
| haproxy | haproxy | >= 0 < 2.6.8-1 | 2.6.8-1 |
| haproxy | haproxy | >= 2.2.0 < 2.2.27 | 2.2.27 |
| haproxy | haproxy | 2.4.0 – 2.4.21 | — |
| haproxy | haproxy | 2.5.0 – 2.5.11 | — |
| haproxy | haproxy | 2.6.0 – 2.6.8 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-0836: An information leak vulnerability was discovered in HAProxy 2
osv·2023-03-29·CVSS 7.5
CVE-2023-0836 [HIGH] CVE-2023-0836: An information leak vulnerability was discovered in HAProxy 2
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
GHSA
GHSA-xhfw-qhxr-hjhq: An information leak vulnerability was discovered in HAProxy 2
ghsa_unreviewed·2023-03-29
CVE-2023-0836 [HIGH] CWE-200 GHSA-xhfw-qhxr-hjhq: An information leak vulnerability was discovered in HAProxy 2
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
Ubuntu
HAProxy vulnerability
vendor_ubuntu·2023-04-03
CVE-2023-0836 HAProxy vulnerability
Title: HAProxy vulnerability
Summary: HAProxy could be made to expose sensitive information over the network.
It was discovered that HAProxy incorrectly initialized certain connection
buffers. A remote attacker could possibly use this issue to obtain
sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2023-0836: haproxy - An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2....
vendor_debian·2023·CVSS 7.5
CVE-2023-0836 [HIGH] CVE-2023-0836: haproxy - An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2....
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
Scope: local
bookworm: resolved (fixed in 2.6.8-1)
bullseye: resolved (fixed in 2.2.9-2+deb11u5)
forky: resolved (fixed in 2.6.8-1)
sid: resolved (fixed in 2.6.8-1)
trixie: resolved (fixed in 2.6.8-1)
Red Hat
haproxy: data leak via fcgi requests
vendor_redhat·2022-12-09·CVSS 7.5
CVE-2023-0836 [HIGH] CWE-459 haproxy: data leak via fcgi requests
haproxy: data leak via fcgi requests
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
A flaw was found in HAProxy, which could allow a remote attacker to obtain sensitive information caused by improper initialization when encoding the FCGI_BEGIN_REQUEST record. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information and use this information to launch further attacks against the affected system.
Package: haproxy (Red Hat Ceph S
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-29
Published