SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-11469

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c…

MEDIUM 5.9EPSS 3.02%

Does this matter?

Lower severity and a low EPSS score (3.02%). Track it; it rarely justifies an emergency change on its own.

Description

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check_request_for_cacheability function.

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
3.02% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
haproxy/haproxy · canonical/ubuntu linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.