A user can craft a route that injects a bogus entry into one of the HAProxy configuration files. This bogus entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary application, including one belonging to the user who is performing the attack.
End of life: 8/24/2022, End of support: 10/27/2021, Latest version: 4.7.60
End of life: 8/24/2022, End of support: 10/27/2021, Latest version: 4.7.60