[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2HAPROXY2-2023-007 --- haproxy2

ID: oval:org.secpod.oval:def:1701726Date: (C)2023-10-26   (M)2024-01-08
Class: PATCHFamily: unix




HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an extra request

Platform:
Amazon Linux 2
Product:
haproxy2
Reference:
ALAS2HAPROXY2-2023-007
CVE-2023-40225
CVE    1
CVE-2023-40225
CPE    1
cpe:/o:amazon:linux:2

© SecPod Technologies