7.5

CVE-2024-45506

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haproxy ≫ Haproxy Version >= 2.9.0 < 2.9.10
Haproxy ≫ Haproxy Version >= 3.0.0 < 3.0.4
Haproxy ≫ Haproxy Version 3.1 Update dev0
Haproxy ≫ Haproxy Version 3.1 Update dev1
Haproxy ≫ Haproxy Version 3.1 Update dev2
Haproxy ≫ Haproxy Version 3.1 Update dev3
Haproxy ≫ Haproxy Version 3.1 Update dev4
Haproxy ≫ Haproxy Version 3.1 Update dev5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.2% 0.642
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

https://www.haproxy.org/
Product
http://git.haproxy.org/?p=haproxy-3.0.git%3Ba=commitdiff%3Bh=c725db17e8416ffb3c1537aea756356228ce5e3c
Broken Link
http://git.haproxy.org/?p=haproxy-3.0.git%3Ba=commitdiff%3Bh=d636e515453320c6e122c313c661a8ac7d387c7f
Broken Link
https://www.haproxy.org/download/3.1/src/CHANGELOG
Release Notes
https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html
Release Notes
https://www.mail-archive.com/haproxy%40formilux.org/msg45281.html
Release Notes