CVE-2022-0711

Description

A flaw was found in the way HAProxy processed HTTP responses containing the Set-Cookie2 header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
66.484

Associated Vulnerability

VulnerabilityOS Platform
fast and reliable load balancing reverse proxy (USN-5312-1) haproxy_2.2.9-2ubuntu2.1_amd64.debLinux
fast and reliable load balancing reverse proxy (USN-5312-1) haproxy_2.0.13-2ubuntu0.5_amd64.debLinux
haproxy security update(DSA-5102-1) haproxy_2.2.9-2+deb11u3_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234