CVE-2023-40225
Summary
| CVE | CVE-2023-40225 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-10 21:15:00 UTC |
| Updated | 2023-08-18 20:03:00 UTC |
| Description | HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an extra request. |
Risk And Classification
Problem Types: CWE-444
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| HAProxy forwards malformed empty Content-Length headers, in violation of RFC 9110 · Issue #2237 · haproxy/haproxy · GitHub | MISC | github.com | |
| www.haproxy.org/download/2.8/src/CHANGELOG | MISC | www.haproxy.org | |
| CWE - CWE-436: Interpretation Conflict (4.8) | MISC | cwe.mitre.org | |
| www.haproxy.org/download/2.6/src/CHANGELOG | MISC | www.haproxy.org | |
| BUG/MAJOR: http: reject any empty content-length header value · haproxy/haproxy@6492f1f · GitHub | MISC | github.com | |
| www.haproxy.org/download/2.7/src/CHANGELOG | MISC | www.haproxy.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161397 Oracle Enterprise Linux Security Update for haproxy (ELSA-2024-1142)
- 199664 Ubuntu Security Notification for HAProxy Vulnerability (USN-6294-1)
- 199671 Ubuntu Security Notification for HAProxy Vulnerability (USN-6294-2)
- 242545 Red Hat OpenShift Container Platform 4.13 Security Update (RHSA-2023:7606)
- 242578 Red Hat OpenShift Container Platform 4.14 Security Update (RHSA-2023:7473)
- 242714 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2024:0200)
- 242752 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2024:0308)
- 243015 Red Hat Update for haproxy (RHSA-2024:1089)
- 243020 Red Hat Update for haproxy (RHSA-2024:1142)
- 355867 Amazon Linux Security Advisory for haproxy : ALAS2023-2023-293
- 356291 Amazon Linux Security Advisory for haproxy2 : ALASHAPROXY2-2023-007
- 356507 Amazon Linux Security Advisory for haproxy2 : ALAS2HAPROXY2-2023-007
- 6000407 Debian Security Update for haproxy (DSA 5590-1)
- 673332 EulerOS Security Update for haproxy (EulerOS-SA-2023-3215)
- 673416 EulerOS Security Update for haproxy (EulerOS-SA-2023-2878)
- 673488 EulerOS Security Update for haproxy (EulerOS-SA-2023-3008)
- 673656 EulerOS Security Update for haproxy (EulerOS-SA-2023-3031)
- 673671 EulerOS Security Update for haproxy (EulerOS-SA-2023-3180)
- 673904 EulerOS Security Update for haproxy (EulerOS-SA-2023-2897)
- 770218 Red Hat OpenShift Container Platform 4.13 Security Update (RHSA-2023:7606)
- 770220 Red Hat OpenShift Container Platform 4.14 Security Update (RHSA-2023:7473)
- 770223 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2024:0200)
- 770226 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2024:0308)
- 941615 AlmaLinux Security Update for haproxy (ALSA-2024:1142)