CVE-2019-11323

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
09/05/2019
Last modified:
07/11/2023

Description

HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* 1.9.2 (including) 1.9.7 (excluding)