NA

CVE-2023-0056

Published: 23/03/2023 Updated: 03/04/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An uncontrolled resource consumption vulnerability exists in HAProxy which could crash the service. This issue could allow an authenticated remote malicious user to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

haproxy haproxy -

redhat software collections -

redhat ceph storage 5.0

redhat openshift_container_platform 4.12

redhat openshift_container_platform_for_ibm_linuxone 4.12

redhat openshift_container_platform_for_power 4.12

redhat openshift_container_platform_ibm_z_systems 4.12

redhat openshift container platform 4.12

redhat openshift container platform 4.11

redhat openshift container platform 4.10

redhat openshift_container_platform 4.10

redhat openshift_container_platform_for_ibm_linuxone 4.10

redhat openshift_container_platform_for_power 4.10

redhat openshift_container_platform_ibm_z_systems 4.10

redhat openshift_container_platform 4.11

redhat openshift_container_platform_for_ibm_linuxone 4.11

redhat openshift_container_platform_for_power 4.11

redhat openshift_container_platform_ibm_z_systems 4.11

fedoraproject extra packages for enterprise linux 8.0

fedoraproject fedora 36

fedoraproject fedora 37

Vendor Advisories

Two vulnerabilities were discovered in HAProxy, a fast and reliable load balancing reverse proxy, which may result in denial of service, or bypass of access controls and routing rules via specially crafted requests For the stable distribution (bullseye), these problems have been fixed in version 229-2+deb11u4 We recommend that you upgrade your ...
Synopsis Moderate: haproxy security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for haproxy is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a se ...
Synopsis Moderate: OpenShift Container Platform 4130 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4130 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Important: new container image: rhceph-53 Type/Severity Security Advisory: Important Topic Updated container image for Red Hat Ceph Storage 53 is now available inthe Red Hat Ecosystem CatalogRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base sc ...
Synopsis Moderate: haproxy security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for haproxy is now available for Red Hat Enterprise Linux 90 Extended Update SupportRed Hat Product Security has rated ...
Synopsis Important: OpenShift Container Platform 4130 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Container Platform release 4130 is now available with updates to packages and ima ...
The HAProxy Github issue describes this vulnerability as follows: Crash (SEGV) in http_wait_for_response in 2219, 2224, and 2226 because sl (start line) variable is NULL (CVE-2023-0056) ...