← Back

CVE-2023-25950

nvd nist
Published: Apr 11, 2023Modified: Feb 11, 2025

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: NVD

Description

HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a denial-of-service (DoS) condition.

Affected (2)

Products: Haproxy: Haproxy
1 product
Haproxy
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Haproxy
From 2.6.1 to 2.6.7
Version 2.7.0

References (6)

Source: vultures@jpcert.or.jp
Third Party AdvisoryVDB Entry
Source: vultures@jpcert.or.jp
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.