Database/Control plane, storage & DevOps

HAProxy (before 2.7.3): HAProxy's HTTP/1 header parser accepts empty header field names, which can be used to make
Impact
HAProxy's HTTP/1 header parser accepts empty header field names, which can be used to make legitimate headers silently disappear after parsing. An attacker can use this to smuggle requests past access-control rules that were supposed to inspect those headers — bypassing ACLs meant to keep unauthorized traffic away from backend inference/storage services.
Who can reach it
Remote — an attacker sends a crafted HTTP/1 request with an empty header field name to a HAProxy instance doing header-based ACL enforcement.
What to do
Software upgrade to HAProxy 2.7.3 or later, then reload/restart the process. HAProxy typically runs as a software component rather than an appliance, so this is a package upgrade + service restart across whichever hosts run it in front of the cluster; a graceful reload avoids dropping in-flight connections if your HAProxy version supports it.
References
Related entries
- DMTF libspdm - SPDM session establishment (reference implementation used in GPU/device attestation): A deviceCVE-2023-31127 · DMTF libspdm - SPDM session establishment (reference implementation used in GPU/device attestation)Critical
- Samba: Path traversal in client pipe namesCVE-2023-3961 · SambaCritical
- Lustre (incorrect access control, 2.13.x-2.15.x before 2.15.4): Incorrect access control in Lustre lets an attackerCVE-2023-51786 · Lustre (incorrect access control, 2.13.x-2.15.x before 2.15.4)Critical
- Pure Storage FlashArray Purity (remote administrative account creation): An attacker uses a remote administrativeCVE-2024-0003 · Pure Storage FlashArray Purity (remote administrative account creation)Critical
- Pure Storage FlashArray Purity (array admin command execution): A user holding the array admin role executes arbitraryCVE-2024-0004 · Pure Storage FlashArray Purity (array admin command execution)Critical
- Pure Storage FlashArray / FlashBlade Purity (SNMP configuration command injection): A crafted SNMP configuration yieldsCVE-2024-0005 · Pure Storage FlashArray / FlashBlade Purity (SNMP configuration command injection)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.