« Volver al listado

CVE-2024-53008

Estado: AplazadaMedia (5.3)—

Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-53008",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-53008",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-29T20:53:41.790046Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "vultures@jpcert.or.jp",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "HAProxy Project",
          "product": "HAProxy 2.6",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.18 and earlier"
            }
          ]
        },
        {
          "vendor": "HAProxy Project",
          "product": "HAProxy 2.8",
          "versions": [
            {
              "status": "affected",
              "version": "2.8.10 and earlier"
            }
          ]
        },
        {
          "vendor": "HAProxy Project",
          "product": "HAProxy 2.9",
          "versions": [
            {
              "status": "affected",
              "version": "2.9.9 and earlier"
            }
          ]
        },
        {
          "vendor": "HAProxy Project",
          "product": "HAProxy 3.0",
          "versions": [
            {
              "status": "affected",
              "version": "3.0.2 and earlier"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*"
          ],
          "vendor": "haproxy",
          "product": "haproxy",
          "versions": [
            {
              "status": "affected",
              "version": "2.6",
              "versionType": "custom",
              "lessThanOrEqual": "2.6.18"
            },
            {
              "status": "affected",
              "version": "2.8",
              "versionType": "custom",
              "lessThanOrEqual": "2.8.10"
            },
            {
              "status": "affected",
              "version": "2.9",
              "versionType": "custom",
              "lessThanOrEqual": "2.9.9"
            },
            {
              "status": "affected",
              "version": "3.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.0.2"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-11-28T03:15:16.363",
  "references": [
    {
      "url": "https://git.haproxy.org/?p=haproxy-2.6.git;a=commit;h=1afca10150ac3e4e2224055cc31b6f1e4a70efe2",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://git.haproxy.org/?p=haproxy-2.8.git;a=commit;h=01c1056a44823c5ffb8f74660b32c099d9b5355b",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://git.haproxy.org/?p=haproxy-2.9.git;a=commit;h=4bcaece344c8738dac1ab5bd8cc81e2a22701d71",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://git.haproxy.org/?p=haproxy-3.0.git;a=commit;h=95a607c4b3af09be2a495b9c2872ea252ccff603",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN88385716/",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.haproxy.org/",
      "source": "vultures@jpcert.or.jp"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vultures@jpcert.or.jp",
      "description": [
        {
          "lang": "en",
          "value": "CWE-444"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited,  a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information."
    },
    {
      "lang": "es",
      "value": "Existe un problema de interpretación inconsistente de las solicitudes HTTP ('Contrabando de solicitudes/respuestas HTTP') en HAProxy. Si se aprovecha esta vulnerabilidad, un atacante remoto puede acceder a una ruta restringida por la ACL (lista de control de acceso) establecida en el producto. Como resultado, el atacante puede obtener información confidencial."
    }
  ],
  "lastModified": "2026-06-17T08:08:00.790",
  "sourceIdentifier": "vultures@jpcert.or.jp"
}