Sploitus

CVE-2023-45539

1 known exploit for CVE-2023-45539

HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.

Haproxy
< 2.8.2
Fix
Available
CVSS 3.1
8.2 HIGH
EPSS
1.5% (73th percentile)
Weakness
CWE-116
NVD status
Modified
Published
2023-11-28
CVE-2023-45539 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2023-45539

Proof-of-concept code and exploit modules indexed by Sploitus