CVE-2020-11100
—CVSS 3.1
8.8 high
EPSS
61%p99
Published
()
Modified
Description
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
In the news0 stories
No ingested article mentions this CVE yet.