NA

CVE-2023-0056

Published: 23/03/2023 Updated: 03/04/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An uncontrolled resource consumption vulnerability exists in HAProxy which could crash the service. This issue could allow an authenticated remote malicious user to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

haproxy haproxy -

redhat software collections -

redhat ceph storage 5.0

redhat openshift container platform 4.12

redhat openshift container platform for ibm linuxone 4.12

redhat openshift container platform for power 4.12

redhat openshift container platform ibm z systems 4.12

redhat openshift container platform 4.11

redhat openshift container platform 4.10

redhat openshift container platform for ibm linuxone 4.10

redhat openshift container platform for power 4.10

redhat openshift container platform ibm z systems 4.10

redhat openshift container platform for ibm linuxone 4.11

redhat openshift container platform for power 4.11

redhat openshift container platform ibm z systems 4.11

fedoraproject extra packages for enterprise linux 8.0

fedoraproject fedora 36

fedoraproject fedora 37

Vendor Advisories

Synopsis Important: OpenShift Container Platform 4130 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Container Platform release 4130 is now available with updates to packages and ima ...
Synopsis Moderate: haproxy security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for haproxy is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a se ...
Synopsis Moderate: OpenShift Container Platform 4130 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4130 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Important: new container image: rhceph-53 Type/Severity Security Advisory: Important Topic Updated container image for Red Hat Ceph Storage 53 is now available inthe Red Hat Ecosystem CatalogRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base sc ...
Synopsis Moderate: haproxy security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for haproxy is now available for Red Hat Enterprise Linux 90 Extended Update SupportRed Hat Product Security has rated ...
Two vulnerabilities were discovered in HAProxy, a fast and reliable load balancing reverse proxy, which may result in denial of service, or bypass of access controls and routing rules via specially crafted requests For the stable distribution (bullseye), these problems have been fixed in version 229-2+deb11u4 We recommend that you upgrade your ...
The HAProxy Github issue describes this vulnerability as follows: Crash (SEGV) in http_wait_for_response in 2219, 2224, and 2226 because sl (start line) variable is NULL (CVE-2023-0056) ...