Amazon Linux 2023 Security Advisory: ALAS-2024-496
Advisory Release Date: 2024-01-19 01:31 Pacific
Advisory Updated Date: 2024-01-22 20:30 Pacific
HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server. (CVE-2023-45539)
Affected Packages:
haproxy
Issue Correction:
Run dnf update haproxy --releasever 2023.3.20240122 to update your system.
aarch64:
haproxy-debuginfo-2.8.3-1.amzn2023.aarch64
haproxy-2.8.3-1.amzn2023.aarch64
haproxy-debugsource-2.8.3-1.amzn2023.aarch64
src:
haproxy-2.8.3-1.amzn2023.src
x86_64:
haproxy-debuginfo-2.8.3-1.amzn2023.x86_64
haproxy-2.8.3-1.amzn2023.x86_64
haproxy-debugsource-2.8.3-1.amzn2023.x86_64