ZeroHour

CVE-2021-39240

CVSS 3.1
7.5 high
EPSS
2%p82
Published
()
Modified
Description

An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It does not ensure that the scheme and path portions of a URI have the expected characters. For example, the authority field (as observed on a target HTTP/2 server) might differ from what the routing rules were intended to achieve.

Vendors
haproxydebianfedoraproject
Products
haproxy, debian linux, fedora
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.