CRITICAL 9.1 Microsoft PoC
CVE-2023-25725
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3 the impact is limited because the headers disappear before being parsed and processed as if they had not been sent by the client. The fixed versions are 2.7.3 2.6.9 2.5.12 2.4.22 2.2.29 and 2.0.31.
Microsoft Security Update 2023-Feb: HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3 the impact is limited because the headers disappear before being parsed and processed as if they had not been sent by the client. The fixed versions are 2.7.3 2.6.9 2.5.12 2.4.22 2.2.29 and 2.0.31.
Affected Products
- cm1 haproxy 2.1.5-2 on CBL Mariner 1.0
- cbl2 haproxy 2.4.22-1 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-25725
- https://nvd.nist.gov/vuln/detail/CVE-2023-25725
This critical severity vulnerability with a CVSS score of 9.1 was published on 2023-02-14 via Microsoft. 🚨 A public proof-of-concept exploit is available on GitHub. EPSS score: 5.5% (top 8% of all CVEs by exploitation probability). Affected: cm1 haproxy 2.1.5-2 on CBL Mariner 1.0, cbl2 haproxy 2.4.22-1 on CBL Mariner 2.0.
Risk Timeline
CVE Disclosed2023-02-14 · 1283 days ago
Public PoC Exploit AvailableWeaponised proof-of-concept code is publicly accessible
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2023-25725NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2023-25725Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2021-43267 PoC | An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. | CRITICAL | 9.8 |
| CVE-2021-43523 | In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters i | CRITICAL | 9.6 |
| CVE-2020-25632 | A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation al | HIGH | 8.2 |
| CVE-2021-3935 | When PgBouncer is configured to use "cert" authentication a man-in-the-middle at | HIGH | 8.1 |
| CVE-2021-3968 | Heap-based Buffer Overflow in vim/vim | HIGH | 8.0 |
| CVE-2020-12657 | An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-f | HIGH | 7.8 |
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.