CVE-2023-25950

CVSS V2 None CVSS V3 None
Description
HTTP request/response smuggling vulnerability in HAProxy version 2.7.0, and 2.6.1 to 2.6.7 allows a remote attacker to alter a legitimate user's request. As a result, the attacker may obtain sensitive information or cause a denial-of-service (DoS) condition.
Overview
  • CVE ID
  • CVE-2023-25950
  • Assigner
  • vultures@jpcert.or.jp
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-04-11T09:15:07
  • Last Modified Date
  • 2023-04-21T18:03:17
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* 1 OR 2.6.1 2.6.7
cpe:2.3:a:haproxy:haproxy:2.7.0:*:*:*:*:*:*:* 1 OR
History
Created Old Value New Value Data Type Notes
2023-04-17 04:29:04 Added to TrackCVE
2023-04-17 14:00:45 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-04-18 19:00:32 2023-04-18T16:15:57 CVE Modified Date updated
2023-04-18 19:00:32 Undergoing Analysis Analyzed Vulnerability Status updated
2023-04-18 19:00:34 Weakness Enumeration new
2023-04-18 19:00:36 CPE Information updated
2023-04-21 18:00:54 Analyzed Undergoing Analysis Vulnerability Status updated
2023-04-21 19:00:57 2023-04-21T18:03:17 CVE Modified Date updated
2023-04-21 19:00:57 Undergoing Analysis Analyzed Vulnerability Status updated