CVE-2024-53008
published 2024-11-28CVE-2024-53008: Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker…
PriorityP428medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.04%
60.3th percentile
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | haproxy | < haproxy 2.9.10-1 (forky) | haproxy 2.9.10-1 (forky) |
| haproxy | haproxy | >= 0 < 2.9.10-1 | 2.9.10-1 |
| haproxy | haproxy | >= 0 < 2.9.10-1 | 2.9.10-1 |
| haproxy_project | haproxy_2.6 | — | — |
| haproxy_project | haproxy_2.8 | — | — |
| haproxy_project | haproxy_2.9 | — | — |
| haproxy_project | haproxy_3.0 | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
HAProxy vulnerability
vendor_ubuntu·2024-12-03
CVE-2024-53008 HAProxy vulnerability
Title: HAProxy vulnerability
Summary: HAProxy could be made to expose sensitive information over the
network.
Yuki Mogi discovered that HAProxy incorrectly handled the interpretation
of certain HTTP requests. A remote attacker could possibly use this issue
to perform a request smuggling attack and obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
HAProxy: HTTP request smuggling in HAProxy
vendor_redhat·2024-11-28·CVSS 5.3
CVE-2024-53008 [MEDIUM] CWE-444 HAProxy: HTTP request smuggling in HAProxy
HAProxy: HTTP request smuggling in HAProxy
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information.
A flaw was found in HAProxy. This vulnerability allows a remote attacker to access a path restricted by the Access Control List (ACL) set on the product. As a result, the attacker may obtain sensitive information.
Statement: This vulnerability affects HAProxy: 2.6.0 - 3.0.2.
The affected version of HAProxy is not shipped in RHEL.
Package: haproxy (Red Hat Ceph Storage 5) - Not affected
Package: haproxy (Red Hat Enterprise Linux 7) - Not affec
Debian
CVE-2024-53008: haproxy - Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling')...
vendor_debian·2024·CVSS 5.3
CVE-2024-53008 [MEDIUM] CVE-2024-53008: haproxy - Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling')...
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 2.9.10-1)
sid: resolved (fixed in 2.9.10-1)
trixie: resolved (fixed in 2.9.10-1)
OSV
CVE-2024-53008: Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy
osv·2024-11-28·CVSS 5.3
CVE-2024-53008 [MEDIUM] CVE-2024-53008: Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information.
GHSA
GHSA-qq72-vh82-fwv9: Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy
ghsa_unreviewed·2024-11-28
CVE-2024-53008 [MEDIUM] CWE-444 GHSA-qq72-vh82-fwv9: Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information.
No detection rules found.
No public exploits indexed.
https://git.haproxy.org/?p=haproxy-2.6.git;a=commit;h=1afca10150ac3e4e2224055cc31b6f1e4a70efe2https://git.haproxy.org/?p=haproxy-2.8.git;a=commit;h=01c1056a44823c5ffb8f74660b32c099d9b5355bhttps://git.haproxy.org/?p=haproxy-2.9.git;a=commit;h=4bcaece344c8738dac1ab5bd8cc81e2a22701d71https://git.haproxy.org/?p=haproxy-3.0.git;a=commit;h=95a607c4b3af09be2a495b9c2872ea252ccff603https://jvn.jp/en/jp/JVN88385716/https://www.haproxy.org/
2024-11-28
Published