HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smu
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
2주 이내 패치 — 우선 조치 대상
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H약점 (CWE)
상세 설명
HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- haproxy haproxy< 2.0.31other
- haproxy haproxy2.1.0 - 2.2.29other
- haproxy haproxy2.3.0 - 2.4.22other
- haproxy haproxy2.5.0 - 2.5.12other
- haproxy haproxy2.6.0 - 2.6.9other
- haproxy haproxy2.7.0 - 2.7.3other
- debian debian_linuxlinux
- debian debian_linuxlinux
영향받는 구성 (CPE) 3
- haproxy haproxy< 2.0.31cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*
- debian debian_linux 10.0cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
- debian debian_linux 11.0cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
참고 자료 6
- https://lists.debian.org/debian-lts-announce/2023/02/msg00012.htmlMailing ListThird Party Advisory
- https://www.debian.org/security/2023/dsa-5348Third Party Advisory
- https://www.haproxy.org/Product
링크 내용 불러오는 중…