CVE-2023-0836

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
VendorProductVersion
haproxyhaproxy
2.2.0 ≤
𝑥
< 2.2.27
haproxyhaproxy
2.4.0 ≤
𝑥
≤ 2.4.21
haproxyhaproxy
2.5.0 ≤
𝑥
≤ 2.5.11
haproxyhaproxy
2.6.0 ≤
𝑥
≤ 2.6.8
haproxyhaproxy
2.1.0
haproxyhaproxy
2.3.0
haproxyhaproxy
2.7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
haproxy
bullseye (security)
2.2.9-2+deb11u6
fixed
bullseye
2.2.9-2+deb11u6
fixed
buster
not-affected
bookworm
2.6.12-1+deb12u1
fixed
bookworm (security)
2.6.12-1+deb12u1
fixed
sid
3.0.7-1
fixed
trixie
3.0.7-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
haproxy
lunar
not-affected
kinetic
Fixed 2.4.18-1ubuntu1.3
released
jammy
Fixed 2.4.18-0ubuntu1.3
released
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored