CVE-2023-45539: High severity aprox aproxengine vulnerability
HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a pathend rule, such as routing index.html#.png to a static server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-45539?
CVE-2023-45539 is a vulnerability in HAProxy before 2.8.2 that allows remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule.
How severe is CVE-2023-45539?
CVE-2023-45539 has a severity rating of 8.2, which is considered high.
What is the affected software for CVE-2023-45539?
The affected software for CVE-2023-45539 is HAProxy before version 2.8.2.
How can remote attackers exploit CVE-2023-45539?
Remote attackers can exploit CVE-2023-45539 by including '#' as part of the URI component, which may lead to obtaining sensitive information or misinterpretation of a path_end rule.
How can I fix CVE-2023-45539?
To fix CVE-2023-45539, update HAProxy to version 2.8.2 or later.