CVE-2023-45539 Information
Nov 29, 2023
cve
Description
HAProxy before 2.8.2 accepts as part of the URI component which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule such as routing index.html.png to a static server.
Reference
https://lists.w3.org/Archives/Public/ietf-http-wg/2023JulSep/0070.html https://git.haproxy.org/?p=haproxy.git%3Ba=commit%3Bh=2eab6d354322932cfec2ed54de261e4347eca9a6 https://www.mail-archive.com/haproxy%40formilux.org/msg43861.html
Share on: