CVE Vulnerabilities

CVE-2024-45506

Published: Sep 04, 2024 | Modified: Oct 14, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.

Affected Software

Name Vendor Start Version End Version
Haproxy Haproxy 2.9.0 (including) 2.9.10 (excluding)
Haproxy Haproxy 3.0.0 (including) 3.0.4 (excluding)
Haproxy Haproxy 3.1-dev0 (including) 3.1-dev0 (including)
Haproxy Haproxy 3.1-dev1 (including) 3.1-dev1 (including)
Haproxy Haproxy 3.1-dev2 (including) 3.1-dev2 (including)
Haproxy Haproxy 3.1-dev3 (including) 3.1-dev3 (including)
Haproxy Haproxy 3.1-dev4 (including) 3.1-dev4 (including)
Haproxy Haproxy 3.1-dev5 (including) 3.1-dev5 (including)
Haproxy Ubuntu devel *
Haproxy Ubuntu upstream *

References