First published: Tue Feb 23 2016(Updated: )
It was found that HAProxy statistics are non-authenticated over network. elements/haproxy/os-apply-config/etc/haproxy/haproxy.cfg: listen haproxy.stats :{{#stats.port}}{{stats.port}}{{/stats.port}}{{^stats.port}}1993{{/stats.port}}
Affected Software | Affected Version | How to fix |
---|---|---|
Aprox Aproxengine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1311145 is critical due to the lack of authentication for HAProxy statistics over the network.
To fix REDHAT-BUG-1311145, implement a proper authentication mechanism for the HAProxy statistics endpoint.
The potential risks include unauthorized access to sensitive statistics and possible exploitation by attackers.
REDHAT-BUG-1311145 affects all versions of HAProxy that expose statistics without authentication.
A possible workaround for REDHAT-BUG-1311145 is to restrict access to the statistics interface using firewall rules.