CVE-2023-25725
Summary
| CVE | CVE-2023-25725 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-14 19:15:00 UTC |
| Updated | 2023-11-07 04:09:00 UTC |
| Description | HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Application | Haproxy | Haproxy | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repositories - haproxy-2.7.git/commit | CONFIRM | git.haproxy.org | |
| [SECURITY] Fedora 36 Update: haproxy-2.4.22-2.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 36 Update: haproxy-2.4.22-2.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] [DLA 3318-1] haproxy security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 37 Update: haproxy-2.6.9-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Debian -- Security Information -- DSA-5348-1 haproxy | DEBIAN | www.debian.org | |
| Repositories | git.haproxy.org | ||
| [SECURITY] Fedora 37 Update: haproxy-2.6.9-1.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| www.haproxy.org | MISC | www.haproxy.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160544 Oracle Enterprise Linux Security Update for haproxy (ELSA-2023-1696)
- 181558 Debian Security Update for haproxy (DLA 3318-1)
- 181560 Debian Security Update for haproxy (DSA 5348-1)
- 183481 Debian Security Update for haproxy (CVE-2023-25725)
- 199173 Ubuntu Security Notification for HAProxy Vulnerability (USN-5869-1)
- 241280 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2023:1268)
- 241339 Red Hat Update for haproxy (RHSA-2023:1696)
- 241387 Red Hat Update for haproxy (RHSA-2023:1978)
- 241546 Red Hat OpenShift Container Platform 4.13 Security Update (RHSA-2023:1325)
- 283747 Fedora Security Update for haproxy (FEDORA-2023-7e04833463)
- 283748 Fedora Security Update for haproxy (FEDORA-2023-3e8a21cd5b)
- 356216 Amazon Linux Security Advisory for haproxy2 : ALASHAPROXY2-2023-003
- 672964 EulerOS Security Update for haproxy (EulerOS-SA-2023-1845)
- 672990 EulerOS Security Update for haproxy (EulerOS-SA-2023-1870)
- 673015 EulerOS Security Update for haproxy (EulerOS-SA-2023-1954)
- 673020 EulerOS Security Update for haproxy (EulerOS-SA-2023-1976)
- 673122 EulerOS Security Update for haproxy (EulerOS-SA-2023-2269)
- 673164 EulerOS Security Update for haproxy (EulerOS-SA-2023-2293)
- 753686 SUSE Enterprise Linux Security Update for haproxy (SUSE-SU-2023:0411-1)
- 753687 SUSE Enterprise Linux Security Update for haproxy (SUSE-SU-2023:0412-1)
- 753693 SUSE Enterprise Linux Security Update for haproxy (SUSE-SU-2023:0413-1)
- 770180 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2023:1268)
- 770186 Red Hat OpenShift Container Platform 4.13 Security Update (RHSA-2023:1325)
- 905554 Common Base Linux Mariner (CBL-Mariner) Security Update for haproxy (13575)
- 905569 Common Base Linux Mariner (CBL-Mariner) Security Update for haproxy (13569)
- 905679 Common Base Linux Mariner (CBL-Mariner) Security Update for haproxy (13569-1)
- 906683 Common Base Linux Mariner (CBL-Mariner) Security Update for haproxy (13569-3)
- 907018 Common Base Linux Mariner (CBL-Mariner) Security Update for haproxy (13575-1)
- 940990 AlmaLinux Security Update for haproxy (ALSA-2023:1696)