VulnerabilityModified
CVE-2023-0056
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service.
MEDIUM 6.5EPSS 1.83%
Does this matter?
Lower severity and a low EPSS score (1.83%). Track it; it rarely justifies an emergency change on its own.
Description
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.83% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- haproxy/haproxy · redhat/ceph storage · redhat/software collections · redhat/openshift container platform · redhat/openshift container platform for ibm linuxone · redhat/openshift container platform for power · redhat/openshift container platform ibm z systems · fedoraproject/extra packages for enterprise linux · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2023-0056Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-0056Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.