← Back

CVE-2023-0836

nvd nist
Published: Mar 29, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.

Affected (7)

Products: Haproxy: Haproxy
1 product
Haproxy
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Haproxy
From 2.2.0 to 2.2.27
From 2.4.0 to 2.4.21
From 2.5.0 to 2.5.11
From 2.6.0 to 2.6.8
Version 2.1.0
Version 2.3.0
Version 2.7.0

References (4)

Timeline

No history available yet.