CVE-2023-45539

HIGH LAB

HAProxy <2.8.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.

Exploits (1)

nomisec WORKING POC
by slicingmelon · poc
https://github.com/slicingmelon/HAProxy-CVE-2023-45539-PoC

Scores

CVSS v3 8.2
EPSS 0.0003
EPSS Percentile 7.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Lab Environment

COMMUNITY
Community Lab
docker pull haproxy:2.8.1

Details

CWE
CWE-116
Status published
Products (1)
haproxy/haproxy < 2.8.2
Published Nov 28, 2023
Tracked Since Feb 18, 2026