U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-40225

Change History

Initial Analysis by NIST 8/18/2023 4:03:17 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* versions up to (including) 2.0.32
     *cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* versions from (including) 2.2.0 up to (including) 2.2.30
     *cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* versions from (including) 2.4.0 up to (including) 2.4.23
     *cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* versions from (including) 2.5.0 up to (excluding) 2.6.15
     *cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* versions from (including) 2.7.0 up to (excluding) 2.7.10
     *cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:* versions from (including) 2.8.0 up to (excluding) 2.8.2
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Added CWE

								
							
							
						
NIST CWE-444
Changed Reference Type
https://cwe.mitre.org/data/definitions/436.html No Types Assigned
https://cwe.mitre.org/data/definitions/436.html Technical Description
Changed Reference Type
https://github.com/haproxy/haproxy/commit/6492f1f29d738457ea9f382aca54537f35f9d856 No Types Assigned
https://github.com/haproxy/haproxy/commit/6492f1f29d738457ea9f382aca54537f35f9d856 Patch
Changed Reference Type
https://github.com/haproxy/haproxy/issues/2237 No Types Assigned
https://github.com/haproxy/haproxy/issues/2237 Exploit, Issue Tracking, Vendor Advisory
Changed Reference Type
https://www.haproxy.org/download/2.6/src/CHANGELOG No Types Assigned
https://www.haproxy.org/download/2.6/src/CHANGELOG Release Notes
Changed Reference Type
https://www.haproxy.org/download/2.7/src/CHANGELOG No Types Assigned
https://www.haproxy.org/download/2.7/src/CHANGELOG Release Notes
Changed Reference Type
https://www.haproxy.org/download/2.8/src/CHANGELOG No Types Assigned
https://www.haproxy.org/download/2.8/src/CHANGELOG Release Notes