Vulnerability Description
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Haproxy | Haproxy | - |
| Redhat | Ceph Storage | 5.0 |
| Redhat | Software Collections | - |
| Redhat | Openshift Container Platform | 4.12 |
| Redhat | Openshift Container Platform For Ibm Linuxone | 4.12 |
| Redhat | Openshift Container Platform For Power | 4.12 |
| Redhat | Openshift Container Platform Ibm Z Systems | 4.12 |
| Redhat | Enterprise Linux | 9.0 |
| Fedoraproject | Extra Packages For Enterprise Linux | 8.0 |
| Fedoraproject | Fedora | 36 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2023-0056Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-0056Vendor Advisory
FAQ
What is CVE-2023-0056?
CVE-2023-0056 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious...
How severe is CVE-2023-0056?
CVE-2023-0056 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-0056?
Check the references section above for vendor advisories and patch information. Affected products include: Haproxy Haproxy, Redhat Ceph Storage, Redhat Software Collections, Redhat Openshift Container Platform, Redhat Openshift Container Platform For Ibm Linuxone.