CVE-2019-19330

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
27/11/2019
Last modified:
07/11/2023

Description

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* 2.0.10 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*