An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
References
Link | Resource |
---|---|
https://access.redhat.com/security/cve/CVE-2023-0056 | Vendor Advisory |
https://access.redhat.com/security/cve/CVE-2023-0056 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
|
History
21 Nov 2024, 07:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://access.redhat.com/security/cve/CVE-2023-0056 - Vendor Advisory |
03 Apr 2023, 17:42
Type | Values Removed | Values Added |
---|---|---|
First Time |
Redhat enterprise Linux
Fedoraproject extra Packages For Enterprise Linux Redhat software Collections Redhat Redhat openshift Container Platform For Power Redhat ceph Storage Redhat openshift Container Platform Fedoraproject fedora Haproxy Redhat openshift Container Platform For Ibm Linuxone Haproxy haproxy Fedoraproject Redhat openshift Container Platform Ibm Z Systems |
|
CWE | CWE-400 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
References | (MISC) https://access.redhat.com/security/cve/CVE-2023-0056 - Vendor Advisory | |
CPE | cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:arm64:* cpe:2.3:a:redhat:openshift_container_platform_for_power:4.10:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform_for_ibm_linuxone:4.12:*:*:*:*:*:*:* cpe:2.3:a:redhat:ceph_storage:5.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.12:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform:4.10:*:*:*:*:*:arm64:* cpe:2.3:a:haproxy:haproxy:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:software_collections:-:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform:4.10:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.11:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform_for_power:4.11:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform_for_ibm_linuxone:4.10:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:* cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:arm64:* cpe:2.3:a:redhat:openshift_container_platform_for_ibm_linuxone:4.11:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform_for_power:4.12:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.10:*:*:*:*:*:*:* |
23 Mar 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-03-23 21:15
Updated : 2025-02-25 20:15
NVD link : CVE-2023-0056
Mitre link : CVE-2023-0056
CVE.ORG link : CVE-2023-0056
JSON object : View
Products Affected
redhat
- ceph_storage
- openshift_container_platform_for_ibm_linuxone
- openshift_container_platform_for_power
- openshift_container_platform
- enterprise_linux
- openshift_container_platform_ibm_z_systems
- software_collections
fedoraproject
- extra_packages_for_enterprise_linux
- fedora
haproxy
- haproxy
CWE
CWE-400
Uncontrolled Resource Consumption