« Volver al listado

CVE-2018-20615

Estado: ModificadaAlta (7.5)—

An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-20615",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-03-21T16:00:36.297",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00018.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/106645",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://access.redhat.com/errata/RHBA-2019:0327",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:0275",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://usn.ubuntu.com/3858-1/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.mail-archive.com/haproxy%40formilux.org/msg32304.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00018.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/106645",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHBA-2019:0327",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:0275",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://usn.ubuntu.com/3858-1/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.mail-archive.com/haproxy%40formilux.org/msg32304.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto un problema de lectura fuera de límites en el decodificador del protocolo HTTP/2 en HAProxy, en versiones 1.8.x y 1.9.x hasta la 1.9.0, lo que puede resultar en un cierre inesperado. El procesamiento del flag PRIORITY en un frame HEADERS requiere 5 bytes adicionales y, aunque se omiten estos bytes, la longitud total del frame no se volvió a comprobar para asegurar que estaban presentes en la trama."
    }
  ],
  "lastModified": "2026-06-17T01:53:11.713",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D9F2EFA-B2B2-409C-A97A-E05A4E82BE14",
              "versionEndIncluding": "1.8.19",
              "versionStartIncluding": "1.8.0"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1047461B-5BDA-4E41-A7D9-76B08E900468"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:dev0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A41C4AD-11B0-4676-AD44-A5A96ACF8DE3"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:dev1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46D05CF3-6764-4238-86CF-A2B34668EB7F"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:dev10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDEE25E3-D419-4CF8-ABD7-68F4776C3A74"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:dev11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "386AC3AC-187C-4AB8-8F25-C9F6FBC68EC9"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:dev2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1492C457-1304-42B5-A6AE-2E7355DF5E9A"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:dev3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49C58F7E-BD94-43E0-B375-635228F02D9A"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:dev4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0646A03C-8DD1-44A2-B4A9-F4C493E9BDDF"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:dev5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AC98E81-5377-4729-9AD4-F35BB16E99C7"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:dev6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81BABB2D-8E02-402C-A53D-BB4603D43B77"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:dev7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68AD00F1-BBC4-4FF1-9C44-AF2B7E88F5C6"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:dev8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F9E46AC-2CA0-4AB0-A199-9726FA507F33"
            },
            {
              "criteria": "cpe:2.3:a:haproxy:haproxy:1.9.0:dev9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51C49D8B-3A86-4EBF-83B5-5F5BBE6C088F"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1E78106-58E6-4D59-990F-75DA575BFAD9"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7016A2A-8365-4F1A-89A2-7A19F2BCAE5B"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23A7C53F-B80F-4E6A-AFA9-58EEA84BE11D"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07C312A0-CD2C-4B9C-B064-6409B25C278F"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F87326E-0B56-4356-A889-73D026DB1D4B"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "142AD0DD-4CF3-4D74-9442-459CE3347E3A"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:7.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "041F9200-4C01-4187-AE34-240E8277B54D"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:7.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4EB48767-F095-444F-9E05-D9AC345AB803"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux:7.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F6FA12B-504C-4DBF-A32E-0548557AA2ED"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}