Amazon Linux 2023 Security Advisory: ALAS-2025-791
Advisory Release Date: 2025-01-06 19:21 Pacific
Advisory Updated Date: 2025-01-09 13:05 Pacific
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information. (CVE-2024-53008)
Affected Packages:
haproxy
Issue Correction:
Run dnf update haproxy --releasever 2023.6.20250107 to update your system.
aarch64:
haproxy-debuginfo-2.8.3-1.amzn2023.0.1.aarch64
haproxy-2.8.3-1.amzn2023.0.1.aarch64
haproxy-debugsource-2.8.3-1.amzn2023.0.1.aarch64
src:
haproxy-2.8.3-1.amzn2023.0.1.src
x86_64:
haproxy-debuginfo-2.8.3-1.amzn2023.0.1.x86_64
haproxy-2.8.3-1.amzn2023.0.1.x86_64
haproxy-debugsource-2.8.3-1.amzn2023.0.1.x86_64