#VU79767 Inconsistent interpretation of HTTP requests in HAProxy - CVE-2023-40225
Published: August 21, 2023
HAProxy
HAProxy
Description
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request with empty Content-Length headers to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Remediation
External links
- https://www.haproxy.org/download/2.8/src/CHANGELOG
- https://www.haproxy.org/download/2.6/src/CHANGELOG
- https://cwe.mitre.org/data/definitions/436.html
- https://github.com/haproxy/haproxy/issues/2237
- https://www.haproxy.org/download/2.7/src/CHANGELOG
- https://github.com/haproxy/haproxy/commit/6492f1f29d738457ea9f382aca54537f35f9d856