Updated: 2024-11-23 05:31:24.578665
Description:
HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an extra request.
Links | NIST | CIRCL | RHEL | Ubuntu |
Severity | Score | |
---|---|---|
CVSS Version 2.x | 0 | |
CVSS Version 3.x | HIGH | 7.2 |
OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
---|---|---|---|---|---|---|---|---|
AlmaLinux 9.2 ESU | haproxy | 2.4.17 | 7.2 | HIGH | Released | CLSA-2025:1736503350 | 2025-01-10 22:42:48 | |
CentOS 6 ELS | haproxy | 1.5.18 | 7.2 | HIGH | Not Vulnerable | 2023-08-23 09:13:09 | ||
CentOS 8.4 ELS | haproxy | 1.8.27-2 | 7.2 | HIGH | Not Vulnerable | 2023-08-23 09:13:09 | ||
CentOS 8.5 ELS | haproxy | 1.8.27-2 | 7.2 | HIGH | Not Vulnerable | 2023-08-23 09:13:08 | ||
CloudLinux 6 ELS | haproxy | 1.5.18 | 7.2 | HIGH | Not Vulnerable | 2023-08-23 09:13:09 | ||
Oracle Linux 6 ELS | haproxy | 1.5.18 | 7.2 | HIGH | Not Vulnerable | 2023-08-23 09:13:09 | ||
Ubuntu 16.04 ELS | haproxy | 1.6.3 | 7.2 | HIGH | Not Vulnerable | 2023-08-23 09:13:09 | ||
Ubuntu 18.04 ELS | haproxy | 1.8.8 | 7.2 | HIGH | Not Vulnerable | 2023-08-23 09:13:09 |