Bug 2402538 (CVE-2025-59303) - CVE-2025-59303 haproxy: HAProxy Kubernetes Ingress Controller: Secret Leak via Config Snippets
Summary: CVE-2025-59303 haproxy: HAProxy Kubernetes Ingress Controller: Secret Leak vi...
Keywords:
Status: NEW
Alias: CVE-2025-59303
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2418547
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-10-08 17:01 UTC by OSIDB Bzimport
Modified: 2025-12-10 00:22 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-10-08 17:01:18 UTC
HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in obtaining an ingress token secret as a response. The fixed versions of HAProxy Enterprise Kubernetes Ingress Controller are 3.0.16-ee1, 1.11.13-ee1, and 1.9.15-ee1.


Note You need to log in before you can comment on or make changes to this bug.