CVE-2023-25725
haproxy - security update
9.1
CRITICAL
CVSS 3.1
EPSS 5.5%
描述
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.
如何修補 CVE-2023-25725
要修補 CVE-2023-25725,請將受影響套件升級到下列已修補版本。
- —升級至 2.0.31 或更新版本
- —升級至 2.2.9-2+deb11u4 或更新版本
- —升級至 1.8.19-1+deb10u4 或更新版本
CVE-2023-25725 正在被利用嗎?
中等 — EPSS 為 5.5%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 2.0.31, >= 2.1.0, < 2.2.29, >= 2.3.0, < 2.4.22, >= 2.5.0, < 2.5.12, >= 2.6.0, < 2.6.9, >= 2.7.0, < 2.7.3
- from 0, < 2.2.9-2+deb11u4
- from 0, < 1.8.19-1+deb10u4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |