CVE-2023-0836
Summary
| CVE | CVE-2023-0836 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-29 21:15:00 UTC |
| Updated | 2023-11-07 04:01:00 UTC |
| Description | An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161076 Oracle Enterprise Linux Security Update for haproxy (ELSA-2023-6496)
- 181736 Debian Security Update for haproxy (DSA 5388-1)
- 184718 Debian Security Update for haproxy (CVE-2023-0836)
- 199269 Ubuntu Security Notification for HAProxy Vulnerability (USN-5994-1)
- 242324 Red Hat Update for haproxy (RHSA-2023:6496)
- 356219 Amazon Linux Security Advisory for haproxy2 : ALASHAPROXY2-2023-002
- 673744 EulerOS Security Update for haproxy (EulerOS-SA-2023-2687)
- 673834 EulerOS Security Update for haproxy (EulerOS-SA-2023-2645)
- 941385 AlmaLinux Security Update for haproxy (ALSA-2023:6496)