ALAS-2024-496


Amazon Linux 2023 Security Advisory: ALAS-2024-496
Advisory Release Date: 2024-01-19 01:31 Pacific
Advisory Updated Date: 2024-01-22 20:30 Pacific
Severity: Medium

Issue Overview:

HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server. (CVE-2023-45539)


Affected Packages:

haproxy


Issue Correction:
Run dnf update haproxy --releasever 2023.3.20240122 to update your system.

New Packages:
aarch64:
    haproxy-debuginfo-2.8.3-1.amzn2023.aarch64
    haproxy-2.8.3-1.amzn2023.aarch64
    haproxy-debugsource-2.8.3-1.amzn2023.aarch64

src:
    haproxy-2.8.3-1.amzn2023.src

x86_64:
    haproxy-debuginfo-2.8.3-1.amzn2023.x86_64
    haproxy-2.8.3-1.amzn2023.x86_64
    haproxy-debugsource-2.8.3-1.amzn2023.x86_64