CVE-2018-11469 PUBLISHED

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check_request_for_cacheability function.

EPSS 0.03% · 7.8th percentile

Risk Scores

EPSS Score
0.03%
7.8th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTShaproxy0, 1.7.9-1ubuntu1, 1.7.9-1ubuntu2

Timeline

References

Open in Interactive Console →