cbcvebase.
CVE-2023-0836
published 2023-03-29

CVE-2023-0836: An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.20%
64.7th percentile
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianhaproxy< haproxy 2.6.8-1 (bookworm)haproxy 2.6.8-1 (bookworm)
haproxyhaproxy
haproxyhaproxy
haproxyhaproxy
haproxyhaproxy
haproxyhaproxy>= 0 < 2.2.9-2+deb11u52.2.9-2+deb11u5
haproxyhaproxy>= 0 < 2.6.8-12.6.8-1
haproxyhaproxy>= 0 < 2.6.8-12.6.8-1
haproxyhaproxy>= 0 < 2.6.8-12.6.8-1
haproxyhaproxy>= 2.2.0 < 2.2.272.2.27
haproxyhaproxy2.4.0 – 2.4.21
haproxyhaproxy2.5.0 – 2.5.11
haproxyhaproxy2.6.0 – 2.6.8

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.