CVE-2023-25950
published 2023-04-11CVE-2023-25950: HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a…
PriorityP339high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
2.94%
85.6th percentile
HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a denial-of-service (DoS) condition.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | haproxy | < haproxy 2.6.8-1 (bookworm) | haproxy 2.6.8-1 (bookworm) |
| haproxy | haproxy | — | — |
| haproxy | haproxy | >= 0 < 2.6.8-1 | 2.6.8-1 |
| haproxy | haproxy | >= 0 < 2.6.8-1 | 2.6.8-1 |
| haproxy | haproxy | >= 0 < 2.6.8-1 | 2.6.8-1 |
| haproxy | haproxy | 2.6.1 – 2.6.7 | — |
| haproxy_technologies | haproxy | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
osv7.3HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
haproxy: malformed HTTP header field name can lead to HTTP request/response smuggling
vendor_redhat·2023-04-11·CVSS 7.3
CVE-2023-25950 [HIGH] CWE-444 haproxy: malformed HTTP header field name can lead to HTTP request/response smuggling
haproxy: malformed HTTP header field name can lead to HTTP request/response smuggling
HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a denial-of-service (DoS) condition.
Package: haproxy (Red Hat Ceph Storage 5) - Not affected
Package: haproxy (Red Hat Enterprise Linux 7) - Out of support scope
Package: haproxy (Red Hat Enterprise Linux 8) - Not affected
Package: haproxy (Red Hat Enterprise Linux 9) - Will not fix
Package: haproxy (Red Hat OpenShift Container Platform 3.11) - Out of support scope
Package: haproxy (Red Hat OpenShift Container Platform 4) - Not affected
Package: rh-haproxy18-haproxy (Red Hat Sof
Debian
CVE-2023-25950: haproxy - HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6....
vendor_debian·2023·CVSS 7.3
CVE-2023-25950 [HIGH] CVE-2023-25950: haproxy - HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6....
HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a denial-of-service (DoS) condition.
Scope: local
bookworm: resolved (fixed in 2.6.8-1)
bullseye: resolved
forky: resolved (fixed in 2.6.8-1)
sid: resolved (fixed in 2.6.8-1)
trixie: resolved (fixed in 2.6.8-1)
OSV
CVE-2023-25950: HTTP request/response smuggling vulnerability in HAProxy version 2
osv·2023-04-11·CVSS 7.3
CVE-2023-25950 [HIGH] CVE-2023-25950: HTTP request/response smuggling vulnerability in HAProxy version 2
HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a denial-of-service (DoS) condition.
GHSA
GHSA-g72c-cx82-64hq: HTTP request/response smuggling vulnerability in HAProxy version 2
ghsa_unreviewed·2023-04-11
CVE-2023-25950 [HIGH] CWE-444 GHSA-g72c-cx82-64hq: HTTP request/response smuggling vulnerability in HAProxy version 2
HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a denial-of-service (DoS) condition.
No detection rules found.
No public exploits indexed.
https://git.haproxy.org/?p=haproxy-2.7.git%3Ba=commit%3Bh=3ca4223c5e1f18a19dc93b0b09ffdbd295554d46https://jvn.jp/en/jp/JVN38170084/https://www.haproxy.org/https://git.haproxy.org/?p=haproxy-2.7.git%3Ba=commit%3Bh=3ca4223c5e1f18a19dc93b0b09ffdbd295554d46https://jvn.jp/en/jp/JVN38170084/https://www.haproxy.org/
2023-04-11
Published