CVE-2023-25725

Description from NVD

HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.

Information Acquisition Date:2023-02-19T14:55Z
CVSS 2.0: 0.0 None CVSS 3.x: 9.1 CRITICAL

NVD References

 https://www.haproxy.org/
     source:MISC
     tags:
 https://git.haproxy.org/?p=haproxy-2.7.git;a=commit;h=a0e561ad7f29ed50c473f5a9da664267b60d1112
     source:CONFIRM
     tags:
 [debian-lts-announce] 20230214 [SECURITY] [DLA 3318-1] haproxy security update
     source:MLIST
     tags:
 DSA-5348
     source:DEBIAN
     tags:

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag: Linux(4 tweets)



List of frequently cited URLs

URLNum of Times Referred to
https://cvetrends.com48
https://www.mail-archive.com/haproxy17
https://twitter.com/TheHackersNews/status/16269724036782202884
https://securityonline.info/cve-2023-25725-haproxy-http-req...4
https://news.ycombinator.com/item?id=347980824

▼ Show Information from Twitter(78)


List of frequently cited URLs

URLNum of Times Referred to
cvetrends.com48
www.mail-archive.com17
twitter.com4
securityonline.info4
news.ycombinator.com4

▼ Show Information from Twitter(78)


GitHub Search Results: Up to 10
NameURL
No Data

GitHub Search Results: Up to 10
NameURL
No Data

2023/04/02 Score : 0
Added Har-sia Database : 2023/02/15
Last Modified : 2023/04/02
Highest Scored Date : 2023/02/15
Highest Score : 40