USN-5869-1: HAProxy vulnerability
Bahruz Jabiyev, Anthony Gavazzi, Engin Kirda, Kaan Onarlioglu, Adi Peleg, and Harvey Tuch discovered that HAProxy incorrectly handled empty header names. A remote attacker could possibly use this issue to manipulate headers and bypass certain authentication checks and restrictions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-5869-1?
USN-5869-1 is considered a moderate severity vulnerability that allows remote attackers to manipulate headers.
How do I fix USN-5869-1?
To fix USN-5869-1, upgrade HAProxy to the specified remedial version for your Ubuntu distribution.
Which versions are affected by USN-5869-1?
USN-5869-1 affects HAProxy versions earlier than 2.4.18-1ubuntu1.2, 2.4.18-0ubuntu1.2, 2.0.29-0ubuntu1.3, and 1.8.8-1ubuntu0.13 on specific Ubuntu releases.
What can attackers do with USN-5869-1?
An attacker can potentially exploit USN-5869-1 to manipulate HTTP headers and bypass authentication checks.
Is there a specific workaround for USN-5869-1?
There is no specific workaround; the recommended action is to update to the patched versions of HAProxy.