CVE-2019-19330
Summary
| CVE | CVE-2019-19330 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-27 16:15:00 UTC |
| Updated | 2023-11-07 03:07:00 UTC |
| Description | The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| RFC 7540 - Hypertext Transfer Protocol Version 2 (HTTP/2) |
MISC |
tools.ietf.org |
Third Party Advisory |
| Repositories - haproxy-2.0.git/commit |
|
git.haproxy.org |
|
| Debian -- Security Information -- DSA-4577-1 haproxy |
DEBIAN |
www.debian.org |
Third Party Advisory |
| HAProxy: Remote execution of arbitrary code (GLSA 202004-01) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| USN-4212-1: HAProxy vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Bugtraq: [SECURITY] [DSA 4577-1] haproxy security update |
BUGTRAQ |
seclists.org |
Mailing List, Third Party Advisory |
| Repositories - haproxy.git/commit |
|
git.haproxy.org |
|
| Repositories - haproxy-2.0.git/commit |
MISC |
git.haproxy.org |
Patch |
| Repositories - haproxy.git/commit |
|
git.haproxy.org |
|
| Repositories - haproxy.git/commit |
MISC |
git.haproxy.org |
Patch |
| Repositories - haproxy.git/commit |
MISC |
git.haproxy.org |
Patch |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 770024 Red Hat OpenShift Container Platform 4.4.3 Security Update (RHSA-2020:1936)