Bug 2329284 (CVE-2024-53008) - CVE-2024-53008 HAProxy: HTTP request smuggling in HAProxy
Summary: CVE-2024-53008 HAProxy: HTTP request smuggling in HAProxy
Keywords:
Status: NEW
Alias: CVE-2024-53008
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2329293 2329294 2329292
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-11-28 03:01 UTC by OSIDB Bzimport
Modified: 2025-04-06 18:55 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2024-11-28 03:01:14 UTC
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited,  a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information.

Comment 2 Oyvind Albrigtsen 2025-01-06 09:33:02 UTC
The CVE has been fixed in v3.0.3: https://nvd.nist.gov/vuln/detail/CVE-2024-53008


Note You need to log in before you can comment on or make changes to this bug.